CVE-2021-34429
MediumAdvisory
Published 19 Jul 2021In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.993
- 100th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Encoded URIs can access WEB-INF directory in Eclipse Jetty
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| jetty-webappmaven | 9.4.38.v20210224, 9.4.40.v20210413, 9.4.41.v20210516, 9.4.42.v20210604 | 9.4.43 | 6 |
- OSV records
- GHSA-vjv5-gp2w-65vm
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| neo4jneo4j-helm | 4.3.2-1 | 1 of 1See more | 2,640 |
| druidwiremindVerified publisher | 1.22.1 | 1 of 3See more | 7,930 |
| hivebigdata-chartsVerified publisher | 0.1.8 | 1 of 1See more | 7,166 |
| neo4j-communityequinor-charts | 1.2.5 | 1 of 1See more | 2,751 |
| nifi-registryprofyu | 1.14.0-r001 | 1 of 1See more | 4,621 |
| neo4jneo4j-helm-old | 4.3.2-1 | 1 of 1See more | 2,640 |
| drillwearefrank | 1.3.6 | 1 of 3See more | 9,397 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 56a9453c4064 | jetty-webapp | 9.4.43 | 2 |
| 5200710/ | e34ab066d2ed | jetty-webapp | 9.4.43 | 1 |
| apache/ | 1f96558fd292 | jetty-webapp | 9.4.43 | 1 |
| apache/ | 0cef139b6bf1 | jetty-webapp | 9.4.43 | 1 |
| apache/ | 090b7f87ec7f | jetty-webapp | 9.4.43 | 1 |
| library/ | 348e3f56faa2 | jetty-webapp | 9.4.43 | 1 |