Description
The WEB-INF/web.xml Deployment Descriptor file describes how to deploy a web application in a servlet container such as Tomcat. Normally, this file should not be accessible. However, Acunetix WS was able to read the contents of this file by using various encodings and directory traversal variants.
Remediation
Restrict access to this file.
References
Related Vulnerabilities
WordPress Plugin Video Embed & Thumbnail Generator Information Disclosure (1.1)
Nginx memory disclosure with specially crafted HTTP backend responses
WordPress Plugin Candidate Application Form Arbitrary File Download (1.0)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Information Disclosure (9.7.1)