Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30904
HistoryJun 11, 2021 - 7:28 a.m.

Information Disclosure

2021-06-1107:28:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28
jetty-servlets
information disclosure
protected resources

EPSS

0.006

Percentile

78.9%

jetty-servlets is vulnerable to information disclosure. Lack of proper handling of requests to the ConcatServlet with a doubly encoded path allows an attacker to access protected resources within the WEB-INF directory. For example, sending /concat?/%2557EB-INF/web.xml can retrieve the web.xml file.

References