CVE-2021-28163
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: NVD
Description
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
Affected (33)
Show all products
Eclipse: Jetty · Fedoraproject: Fedora · Apache: Ignite, Solr · Netapp: Cloud Manager, E Series Performance Analyzer, E Series Santricity Os Controller, E Series Santricity Web Services, Element Plug In For Vcenter Server, Santricity Cloud Connector, Snapcenter, Snapcenter Plug In, Storage Replication Adapter For Clustered Data Ontap, Vasa Provider For Clustered Data Ontap, Virtual Storage Console · Oracle: Autovue For Agile Product Lifecycle Management, Banking Apis, Banking Digital Experience, Communications Element Manager, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Siebel Core Automation
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 32 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| From 11.0.0 to 11.70.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| From 9.6 | |
| From 9.6 | |
| From 9.6 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 21.0.2 | |
| Version 20.1 | |
| Version 20.1 | |
| Version 8.2.2 | |
| Version 7.0 | |
| From 8.0.0 to 8.2.4.0 | |
| From 8.0.0 to 8.2.4.0 | |
| Up to 21.9 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-59
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
References (52)
Source: emo@eclipse.org
ExploitThird Party Advisory
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Not ApplicableThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.