Input validation error in Jetty - CVE-2021-28164

 

Input validation error in Jetty - CVE-2021-28164

Published: April 1, 2021 / Updated: November 25, 2021


Vulnerability identifier: #VU51877
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28164
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive informatoin.

The vulnerability exists due to insufficient validation of user-supplied input when processing special characters, passed via URI. A remote attacker can use %2e or %2e%2e segments to access protected resources within the WEB-INF directory.

Example:

http://[host]/context/%2e/WEB-INF/web.xml


Affected software

Jetty
Red Hat Developer Tools
Sterling Connect:Direct Browser User Interface
Rational Change
AMQ Streams
AMQ Broker
Fuse
IBM Analytic Accelerator Framework for Communication Service Providers
IBM Qradar SIEM
Rational Performance Tester
Oracle Banking Digital Experience
IBM Customer and Network Analytics for Communications Service Providers and Datasets
Oracle Banking APIs
Netcool Operations Insight
Red Hat Integration Camel-K
IBM MaaS360 Mobile Enterprise Gateway
Dell NetWorker Virtual Edition
SUSE Linux Enterprise Module for Development Tools
Anolis OS
Fedora
Dell EMC Storage Monitoring and Reporting (SMR)
jetty
rh-eclipse-jetty (Red Hat package)
jetty-server
jetty-http
jetty-io
jetty-util-ajax
jetty-util
jetty-servlet
jetty-security
jetty-xml
jetty-webapp
jetty-jmx
jetty-javadoc
jetty-jaas
jetty-continuation
jetty-client
IBM InfoSphere Information Server

How to mitigate CVE-2021-28164

Install updates from vendor's website.

Jetty - update to 9.4.39.v20210325
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-32
AMQ Streams - addressed in versions 1.6.4, 1.8.0
IBM Analytic Accelerator Framework for Communication Service Providers - update to 3.6.0.12.0
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
AMQ Broker - addressed in versions 7.8.2, 7.9.0
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 9.6.0.12.3
Netcool Operations Insight - update to 1.6.7
Red Hat Integration Camel-K - update to 1.8
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
Fuse - update to 7.10.0
jetty - addressed in versions 9.4.40-1.fc32, 9.4.40-1.fc33, 9.4.40-1.fc34
rh-eclipse-jetty (Red Hat package) - update to 9.4.40-1.1.el7_9
jetty-server - update to 9.4.42-3.9.1
jetty-http - update to 9.4.42-3.9.1
jetty-io - update to 9.4.42-3.9.1
jetty-util-ajax - update to 9.4.42-3.9.1
jetty-util - update to 9.4.42-3.9.1
jetty-servlet - update to 9.4.42-3.9.1
jetty-security - update to 9.4.42-3.9.1
jetty-xml - update to 9.4.43-1
jetty-webapp - update to 9.4.43-1
jetty-util-ajax - update to 9.4.43-1
jetty-util - update to 9.4.43-1
jetty-servlet - update to 9.4.43-1
jetty-server - update to 9.4.43-1
jetty-security - update to 9.4.43-1
jetty-jmx - update to 9.4.43-1
jetty-javadoc - update to 9.4.43-1
jetty-jaas - update to 9.4.43-1
jetty-io - update to 9.4.43-1
jetty-http - update to 9.4.43-1
jetty-continuation - update to 9.4.43-1
jetty-client - update to 9.4.43-1
jetty - update to 9.4.43-1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Dell NetWorker Virtual Edition - addressed in versions 19.8.0.4, 19.9.0.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins