VDB
RHSA-2022%3A7257
RHSA-2022%3A7257
PUBLISHED
CVSS 5.300000190734863 MEDIUM
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHINT Camel-K 1.8.1 |
Timeline
- Oct 27, 2022 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2022:7257 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2022-Q4 advisory
- https://access.redhat.com/documentation/en-us/red_hat_integration/2022.q4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1971016 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2099553 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7257.json advisory
- https://access.redhat.com/security/cve/CVE-2021-28169 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-28169 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-28169 advisory
- https://access.redhat.com/security/cve/CVE-2022-30973 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-30973 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30973 advisory