Eclipse Jetty 9.4.37, vulnerable to CVE-2021-28164: a URI with an encoded dot segment such as /%2e/WEB-INF/web.xml passes the protected-path check and is then normalised, so files under WEB-INF are served.
Pas commencéDockercommit 416f8afx86_64 · aarch64Secret
Exploit CVE-2021-28164 to read the protected WEB-INF files of the Jetty application.
Le brief de ce lab se trouve dans son dépôt.