cbcvebase.
CVE-2021-28163
published 2021-04-01

CVE-2021-28163: In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of…

low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
apacheignite< 2.1.12.1.1
apachesolr
debianjetty9< jetty9 9.4.39-1 (bookworm)jetty9 9.4.39-1 (bookworm)
eclipsejetty
eclipsejetty
eclipsejetty
eclipsejetty
eclipsejetty>= 9.4.32 < 9.4.399.4.39
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
netappe-series_santricity_os_controller11.0.0 – 11.70.1
netappstorage_replication_adapter_for_clustered_data_ontap>= 9.6
netappvasa_provider_for_clustered_data_ontap>= 9.6
netappvirtual_storage_console>= 9.6
oracleautovue_for_agile_product_lifecycle_management
oraclebanking_apis
oraclebanking_apis
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclecommunications_element_manager
oraclecommunications_services_gatekeeper
oraclecommunications_session_report_manager8.0.0 – 8.2.4.0
oraclecommunications_session_route_manager8.0.0 – 8.2.4.0
oraclesiebel_core_automation<= 21.9

CVSS provenance

nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
osv2.7LOW