id: jetty-showcontexts-enable info: name: Jetty showContexts Enable in DefaultHandler author: dhiyaneshDK severity: low description: Jetty showContexts is Enabled in DefaultHandler reference: - https://github.com/jaeles-project/jaeles-signatures/blob/master/common/jetty-showcontexts-enable.yaml - https://swarm.ptsecurity.com/jetty-features-for-hacking-web-apps/ classification: cpe: cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: eclipse product: jetty shodan-query: html:"contexts known to this" tags: jetty,misconfig http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: word words: - "Contexts known to this server are:" - type: status status: - 404 # digest: 490a0046304402205ee09bc14143b8afefc0e63fe52b9a915d30282d998d20b1d80defa9911cccda022024b08161ddc4d2ed5ca69104854cdd3fd323645e57c0a072d0a25bf9c582fb4d:922c64590222798bb761d5b6d8e72950