Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-28164 PoC — Eclipse Jetty 安全漏洞

Source
Associated Vulnerability
Title:Eclipse Jetty 安全漏洞 (CVE-2021-28164)
Description:In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
Description
jetty /CVE-2021-28164/분석 및 결과
Readme
# -jettyCVE-2021-28164-
jetty /CVE-2021-28164/분석 및 결과
File Snapshot

[4.0K] /data/pocs/d6b4f19b88813075fa9bd4e251f11f3f485ae8f8 ├── [ 482] 분석결과 ├── [ 64] README.md ├── [483K] WHS_1.png └── [360K] WHS_2.png 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →