<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:53:26 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05510</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05510</link>
      <description>bdu:2022-05510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05510</guid>
    </item>
    <item>
      <title>certfr-2021-avi-951 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</link>
      <description>certfr-2021-avi-951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</guid>
    </item>
    <item>
      <title>cnvd-2021-27374</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-27374</link>
      <description>cnvd-2021-27374</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-27374</guid>
    </item>
    <item>
      <title>EUVD-2026-25867</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-25867</link>
      <description>EUVD-2026-25867</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-25867</guid>
    </item>
    <item>
      <title>fkie_cve-2021-28164</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28164</link>
      <description>&lt;p&gt;In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-28164</guid>
    </item>
    <item>
      <title>GHSA-v7ff-8wcx-gmc5 — Authorization Before Parsing and Canonicalization in jetty</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v7ff-8wcx-gmc5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-webapp&lt;/p&gt;
&lt;p&gt;Release 9.4.37 introduced a more precise implementation of [RFC3986](https://tools.ietf.org/html/rfc3986#section-3.3) with regards to URI decoding, together with some new compliance modes to optionally allow support of some URI that may have ambiguous interpretation within the Servlet specified API methods behaviours.   The default mode allowed % encoded . characters to be excluded for URI normalisation, which is correct by the RFC, but is not assumed by common Servlet implementations. The default compliance mode allows requests with URIs that contain `%2e` or `%2e%2e` segments to access protected resources within the `WEB-INF` directory.  For example a request to `/context/%2e/WEB-INF/web.xml` can retrieve the `web.xml` file.  This can reveal sensitive information regarding the implementation of a web application. Workarounds found by HttpCompliance mode RFC7230_NO_AMBIGUOUS_URIS can be enabled by updating `start.d/http.ini` to include: jetty.http.compliance=RFC7230_NO_AMBIGUOUS_URIS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.eclipse.jetty:jetty-webapp&lt;/p&gt;
&lt;p&gt;Release 9.4.37 introduced a more precise implementation of [RFC3986](https://tools.ietf.org/html/rfc3986#section-3.3) with regards to URI decoding, together with some new compliance modes to optionally allow support of some URI that may have ambiguous interpretation within the Servlet specified API methods behaviours.   The default mode allowed % encoded . characters to be excluded for URI normalisation, which is correct by the RFC, but is not assumed by common Servlet implementations. The default compliance mode allows requests with URIs that contain `%2e` or `%2e%2e` segments to access protected resources within the `WEB-INF` directory.  For example a request to `/context/%2e/WEB-INF/web.xml` can retrieve the `web.xml` file.  This can reveal sensitive information regarding the implementation of a web application. Workarounds found by HttpCompliance mode RFC7230_NO_AMBIGUOUS_URIS can be enabled by updating `start.d/http.ini` to include: jetty.http.compliance=RFC7230_NO_AMBIGUOUS_URIS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v7ff-8wcx-gmc5</guid>
    </item>
    <item>
      <title>gsd-2021-28164</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-28164</link>
      <description>gsd-2021-28164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-28164</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1</link>
      <description>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:2005-1</guid>
    </item>
    <item>
      <title>RHSA-2021:1509 — Red Hat Security Advisory: rh-eclipse-jetty security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1509</link>
      <description>&lt;p&gt;jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jetty: Symlink directory exposes webapp directory contents jetty: Ambiguous paths can access WEB-INF jetty: Resource exhaustion when receiving an invalid large TLS frame&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1509</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2005-1 — Security update for jetty-minimal</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1</link>
      <description>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jetty-minimal&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2005-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-28164</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28164</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: equinox-bundles, Ubuntu:20.04:LTS: equinox-bundles, Ubuntu:22.04:LTS: equinox-bundles&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: equinox-bundles, Ubuntu:20.04:LTS: equinox-bundles, Ubuntu:22.04:LTS: equinox-bundles&lt;/p&gt;
&lt;p&gt;In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-28164</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1365 — Eclipse Jetty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um Informationen offenzulegen und einen Denial of Service Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1365</guid>
    </item>
  </channel>
</rss>
