Improper access control in Jetty - CVE-2021-34429
Published: September 30, 2021 / Updated: November 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper input validation when processing certain characters in URI. A remote attacker can send a specially crafted HTTP request with encoded characters in URI, bypass implemented security restrictions and access content of the WEB-INF directory.
Affected software
Sterling Connect:Direct Browser User Interface
Rational Change
Oracle Financial Services Crime and Compliance Management Studio
Oracle Business Process Management Suite
Stream Analytics
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Binding Support Function
IBM Sterling Secure Proxy
Oracle Communications Diameter Signaling Router
IBM Customer and Network Analytics for Communications Service Providers and Datasets
Netcool Operations Insight
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling B2B Integrator
Dell NetWorker Virtual Edition
IBM Analytic Accelerator Framework for Communication Service Providers
IBM Qradar SIEM
AMQ Broker
AMQ Streams
Rational Performance Tester
Oracle Data Integrator
SUSE Linux Enterprise Module for Development Tools
Anolis OS
Oracle Retail EFTLink
Oracle Autovue for Agile Product Lifecycle Management
jetty-javadoc
jetty-continuation
jetty-jaas
jetty-io
jetty-http
jetty
jetty-client
jetty-jmx
jetty-security
jetty-server
jetty-servlet
jetty-util
jetty-util-ajax
jetty-webapp
jetty-xml
IBM InfoSphere Information Server
Oracle REST Data Services
How to mitigate CVE-2021-34429
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-32
IBM Analytic Accelerator Framework for Communication Service Providers - update to 3.6.0.12.0
Rational Change - update to 5.3.2.5
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
AMQ Broker - update to 7.9.0
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 9.6.0.12.3
Stream Analytics - update to 19.1.0.0.6.4
Netcool Operations Insight - update to 1.6.9
AMQ Streams - update to 2.0.0
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.2, 6.1.2.0
jetty-javadoc - update to 9.4.43-1
jetty-continuation - update to 9.4.43-1
jetty-jaas - update to 9.4.43-1
jetty-io - update to 9.4.43-1
jetty-http - update to 9.4.43-1
jetty - update to 9.4.43-1
jetty-client - update to 9.4.43-1
jetty-jmx - update to 9.4.43-1
jetty-security - update to 9.4.43-1
jetty-server - update to 9.4.43-1
jetty-servlet - update to 9.4.43-1
jetty-util - update to 9.4.43-1
jetty-util-ajax - update to 9.4.43-1
jetty-webapp - update to 9.4.43-1
jetty-xml - update to 9.4.43-1
jetty-server - update to 9.4.43-3.12.2
jetty-http - update to 9.4.43-3.12.2
jetty-io - update to 9.4.43-3.12.2
jetty-util-ajax - update to 9.4.43-3.12.2
jetty-util - update to 9.4.43-3.12.2
jetty-servlet - update to 9.4.43-3.12.2
jetty-security - update to 9.4.43-3.12.2
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Dell NetWorker Virtual Edition - addressed in versions 19.8.0.4, 19.9.0.2
Oracle REST Data Services - update to 22.1.1
Links to Public Exploits and PoC-codes
External References
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-vjv5-gp2w-65vm
- https://lists.apache.org/thread.html/r763840320a80e515331cbc1e613fa93f25faf62e991974171a325c82@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r7dd079fa0ac6f47ba1ad0af98d7d0276547b8a4e005f034fb1016951@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r90e7b4c42a96d74c219e448bee6a329ab0cd3205c44b63471d96c3ab@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r46f748c1dc9cf9b6c1c18f6b5bfc3a869907f68f72e17666f2f30f24@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r029c0c6833c8bb6acb094733fd7b75029d633f47a92f1c9d14391fc0@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r8e6c116628c1277c3cf132012a66c46a0863fa2a3037c0707d4640d4@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2a3ea27cca2ac7352d392b023b72e824387bc9ff16ba245ec663bdc6@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rc26807be68748b3347decdcd03ae183622244b0b4cb09223d4b7e500@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rb33d65c3e5686f2e3b9bb8a032a44163b2f2ad9d31a8727338f213c1@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r9e6158d72ef25077c2dc59fbddade2eacf7d259a2556c97a989f2fe8@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r3aefe613abce594c71ace50088d2529bbde65d08b8e7ff2c2723aaa1@%3Cdev.santuario.apache.org%3E
- https://lists.apache.org/thread.html/r6e6f50c1ce1fb592cb43e913f5be23df104d50751465f8f1952ace0c@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r46900f74dbb7d168aeac43bf0e7f64825376bb7eb74d31a5b33344ce@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r679d96f981d4c92724090ed2d5e8565a1d655a72bb315550489f052e@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r756443e9d50af7e8c3df82e2c45105f452c8e8195ddbc0c00f58d5fe@%3Ccommits.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r9d245c6c884bbc804a472116d730c1a01676bf24f93206a34923fc64@%3Ccommits.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r02f940c27e997a277ff14e79e84551382e1081e8978b417e0c2b0857@%3Ccommits.kafka.apache.org%3E
- https://lists.apache.org/thread.html/re5e9bb535db779506013ef8799dc2a299e77cdad6668aa94c456dba6@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r74fdc446df551fe89a0a16957a1bfdaad19380e0c1afd30625685a9c@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/re01890eef49d4201018f2c97e26536e3e75f441ecdbcf91986c3bc17@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/re3de01414ccf682fe0951205f806dd8e94440798fd64c55a4941de3e@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r4727d282b5c2d951057845a46065d59f6e33132edc0a14f41c26b01e@%3Cdev.kafka.apache.org%3E
- https://security.netapp.com/advisory/ntap-20210819-0006/
- https://lists.apache.org/thread.html/r5678d994d4dd8e7c838eed3bbc1a83a7f6bc62724b0cce67e8892a45@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2e32390cb7aedb39069e5b18aa130ca53e766258518faee63c31d3ea@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rcb157f55b9ae41b3076801de927c6fca1669c6d8eaf11a9df5dbeb46@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rcea249eb7a0d243f21696e4985de33f3780399bf7b31ea1f6d489b8b@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r44ea39ca8110de7353bfec88f58aa3aa58a42bb324b8772512ee190c@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0626f279ebf65506110a897e3a57ccd4072803ee5434b2503e070398@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r48a93f2bc025acd7c7e341ed3864bfdeb75f0c768d41bc247e1a1f63@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r833a4c8bdbbfeb8a2cd38238e7b59f83edd5c1a0e508b587fc551a46@%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/r721ab6a5fa8d45bec76714b674f5d4caed2ebfeca69ad1d6d4caae6c@%3Cdev.hbase.apache.org%3E
- https://lists.apache.org/thread.html/re850203ef8700cb826534dd4a1cb9f5b07bb8f6f973b39ff7838d3ba@%3Cissues.hbase.apache.org%3E
Related Security Bulletins
- Information disclosure in Eclipse Jetty
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Retail EFTLink
- Multiple vulnerabilities in IBM MaaS360 Mobile Enterprise Gateway
- SUSE update for jetty-minimal
- Multiple vulnerabilities in IBM Sterling Connect:Direct Browser User Interface
- Multiple vulnerabilities in Oracle REST Data Services
- Multiple vulnerabilities in Oracle Financial Services Crime and Compliance Management Studio
- Improper access control in Oracle Autovue for Agile Product Lifecycle Management
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in IBM Sterling B2B Integrator
- Multiple vulnerabilities in Oracle Data Integrator
- Multiple vulnerabilities in Stream Analytics
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Oracle Business Process Management Suite
- Multiple vulnerabilities in IBM Analytic Accelerator Framework for Communication Service Providers & IBM Customer and Network Analytics
- Multiple vulnerabilities in Dell NetWorker Virtual Edition
- Multiple vulnerabilities in AMQ Streams 2.0
- Anolis OS update for jetty