VDB
Sign up
MEDIUM5.3

GHSA-gwcr-j4wh-j3cq

Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability

Quick fix

GHSA-gwcr-j4wh-j3cq — org.eclipse.jetty:jetty-servlets: upgrade to the fixed version with the command below.

# pom.xml: bump <version>9.4.41</version> for org.eclipse.jetty:jetty-servlets

Details

Requests to the `ConcatServlet` and `WelcomeFilter` are able to access protected resources within the `WEB-INF` directory. For example a request to the `ConcatServlet` with a URI of `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

This occurs because both `ConcatServlet` and `WelcomeFilter` decode the supplied path to verify it is not within the `WEB-INF` or `META-INF` directories. It then uses this decoded path to call `RequestDispatcher` which will also do decoding of the path. This double decoding allows paths with a doubly encoded `WEB-INF` to bypass this security check.

### Impact This affects all versions of `ConcatServlet` and `WelcomeFilter` in versions before 9.4.41, 10.0.3 and 11.0.3.

### Workarounds

If you cannot update to the latest version of Jetty, you can instead deploy your own version of the [`ConcatServlet`](https://github.com/eclipse/jetty.project/blob/4204526d2fdad355e233f6bf18a44bfe028ee00b/jetty-servlets/src/main/java/org/eclipse/jetty/servlets/ConcatServlet.java) and/or the [`WelcomeFilter`](https://github.com/eclipse/jetty.project/blob/4204526d2fdad355e233f6bf18a44bfe028ee00b/jetty-servlets/src/main/java/org/eclipse/jetty/servlets/WelcomeFilter.java) by using the code from the latest version of Jetty.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.eclipse.jetty:jetty-servlets
Introduced in: 0Fixed in: 9.4.41
Fix# pom.xml: bump <version>9.4.41</version> for org.eclipse.jetty:jetty-servlets
Maven/org.eclipse.jetty:jetty-servlets
Introduced in: 10.0.0Fixed in: 10.0.3
Fix# pom.xml: bump <version>10.0.3</version> for org.eclipse.jetty:jetty-servlets
Maven/org.eclipse.jetty:jetty-servlets
Introduced in: 11.0.0Fixed in: 11.0.3
Fix# pom.xml: bump <version>11.0.3</version> for org.eclipse.jetty:jetty-servlets

References