Security readout for executives and security teams
Plain-English summary
CVE-2021-28169 lets an unauthenticated remote requester use Jetty's ConcatServlet to read protected WEB-INF files when paths are doubly encoded. The business risk is disclosure of application internals, configuration, or deployment details, not direct code execution. Treat internet-facing Jetty apps using ConcatServlet as priority patch candidates.
Executive priority
Prioritize remediation for internet-facing Jetty applications because the issue is remotely reachable without authentication. It is moderate severity because impact is limited to information disclosure, but exposed configuration details can support later compromise.
Technical view
Jetty versions <= 9.4.40, <= 10.0.2, and <= 11.0.2 mishandle doubly encoded paths in ConcatServlet, allowing access to protected WEB-INF resources. CVSS 3.1 is 5.3 with network access, low complexity, no privileges, no user interaction, and low confidentiality impact only.
Likely exposure
Exposure is most likely where Jetty serves web applications that enable or package ConcatServlet, especially public applications with sensitive WEB-INF metadata. The source bundle does not prove all Jetty deployments are exploitable.
Exploitation context
The bundle provides a request pattern example and marks KEV as false. No cited source in the bundle supports active exploitation in the wild, so exploitation should be treated as plausible but not confirmed.
Researcher notes
Focus triage on ConcatServlet reachability and protected WEB-INF resource exposure. Do not assume arbitrary file read or code execution from this CVE alone. Downstream Apache Kafka and ZooKeeper references show dependency-driven exposure and upgrades, not independent product-specific exploit details.
Mitigation direction
- Upgrade Jetty beyond the affected versions using Eclipse vendor guidance.
- For Jetty 9.4 deployments, downstream sources reference upgrades to 9.4.41 or 9.4.42.
- Review packaged applications such as Kafka or ZooKeeper for bundled Jetty dependencies.
- Restrict or disable ConcatServlet where it is unnecessary.
- Avoid exposing Jetty management or application surfaces directly to the internet.
Validation and detection
- Inventory applications and transitive dependencies using Eclipse Jetty.
- Confirm whether ConcatServlet is enabled or reachable in deployed web applications.
- Check Jetty versions against <= 9.4.40, <= 10.0.2, and <= 11.0.2.
- Review logs for unusual encoded requests targeting WEB-INF resources.
- Verify downstream products have applied their Jetty security updates.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-200: Information exposure and cloud metadata lookup
Information exposure and SSRF weaknesses can make discovery, cloud metadata, and credential material review relevant. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-28169 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N3.91.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.3MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-gwcr-j4wh-j3cqCVE reference · x_refsource_CONFIRM
- [kafka-users] 20210617 vulnerabilitiesCVE reference · mailing-list, x_refsource_MLIST
- [debian-lts-announce] 20210617 [SECURITY] [DLA 2688-1] jetty9 security updateCVE reference · mailing-list, x_refsource_MLIST
- [kafka-jira] 20210623 [GitHub] [kafka] dongjinleekr opened a new pull request #10919: KAFKA-12985: CVE-2021-28169 - Upgrade jetty to 9.4.41CVE reference · mailing-list, x_refsource_MLIST
- [kafka-dev] 20210623 [jira] [Created] (KAFKA-12985) CVE-2021-28169 - Upgrade jetty to 9.4.41CVE reference · mailing-list, x_refsource_MLIST
- [kafka-jira] 20210623 [jira] [Created] (KAFKA-12985) CVE-2021-28169 - Upgrade jetty to 9.4.41CVE reference · mailing-list, x_refsource_MLIST
- [kafka-jira] 20210704 [GitHub] [kafka] ijuma commented on pull request #10919: KAFKA-12985: CVE-2021-28169 - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [kafka-jira] 20210704 [GitHub] [kafka] ijuma merged pull request #10919: KAFKA-12985: CVE-2021-28169 - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [kafka-dev] 20210722 [jira] [Resolved] (KAFKA-12985) CVE-2021-28169 - Upgrade jetty to 9.4.41CVE reference · mailing-list, x_refsource_MLIST
- [kafka-jira] 20210722 [jira] [Updated] (KAFKA-12985) CVE-2021-28169 - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [kafka-jira] 20210722 [jira] [Resolved] (KAFKA-12985) CVE-2021-28169 - Upgrade jetty to 9.4.41CVE reference · mailing-list, x_refsource_MLIST
- DSA-4949CVE reference · vendor-advisory, x_refsource_DEBIAN
- [zookeeper-issues] 20210928 [jira] [Updated] (ZOOKEEPER-4390) CVE-2021-28169 - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [zookeeper-issues] 20210928 [jira] [Created] (ZOOKEEPER-4390) CVE-2021-28169 - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [zookeeper-issues] 20210928 [jira] [Updated] (ZOOKEEPER-4390) CVE-2021-28169 , - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [zookeeper-issues] 20210928 [jira] [Updated] (ZOOKEEPER-4390) CVE-2021-28169 , CVE-2021-28163, - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [zookeeper-dev] 20210928 [jira] [Created] (ZOOKEEPER-4390) CVE-2021-28169 - Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- [zookeeper-issues] 20210928 [jira] [Updated] (ZOOKEEPER-4390) CVE-2021-28169 , CVE-2021-28163, CVE-2021-34428- Upgrade jetty to 9.4.42CVE reference · mailing-list, x_refsource_MLIST
- https://www.oracle.com/security-alerts/cpuoct2021.htmlCVE reference · x_refsource_MISC
- https://lists.apache.org/thread.html/r8a1a332899a1f92c8118b0895b144b27a78e3f25b9d58a34dd5eb084%40%3Cnotifications.zookeeper.apache.org%3ECVE reference · x_refsource_MISC
- https://lists.apache.org/thread.html/rbefa055282d52d6b58d29a79fbb0be65ab0a38d25f00bd29eaf5e6fd%40%3Cnotifications.zookeeper.apache.org%3ECVE reference · x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20210727-0009/CVE reference · x_refsource_CONFIRM
- https://www.oracle.com/security-alerts/cpujan2022.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
