In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:eclipse:jetty:9.4.37:20210219:*:*:*:*:*:*"
],
"vendor_product": "eclipse:jetty",
"extracted_events": [
{
"last_affected": "9.4.37-20210219"
},
{
"last_affected": "9.4.37-20210219"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*"
],
"vendor_product": "netapp:e-series_santricity_os_controller",
"extracted_events": [
{
"introduced": "11.0"
},
{
"last_affected": "11.70.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_data_ontap:*:*:*:*:*:vmware_vsphere:*:*"
],
"vendor_product": "netapp:storage_replication_adapter_for_clustered_data_ontap",
"extracted_events": [
{
"introduced": "9.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:*:*:*:*:*:*:*:*"
],
"vendor_product": "netapp:vasa_provider_for_clustered_data_ontap",
"extracted_events": [
{
"introduced": "9.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:vmware_vsphere:*:*"
],
"vendor_product": "netapp:virtual_storage_console",
"extracted_events": [
{
"introduced": "9.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.0.2:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:autovue_for_agile_product_lifecycle_management",
"extracted_events": [
{
"last_affected": "21.0.2"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_apis",
"extracted_events": [
{
"last_affected": "20.1"
},
{
"last_affected": "21.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_digital_experience",
"extracted_events": [
{
"last_affected": "20.1"
},
{
"last_affected": "21.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_session_route_manager",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:siebel_core_-_automation:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:siebel_core_-_automation",
"extracted_events": [
{
"last_affected": "21.9"
}
]
}
]
}