// For flags

CVE-2021-28163

jetty: Symlink directory exposes webapp directory contents

Severity Score

2.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

En Eclipse Jetty versiones 9.4.32 hasta 9.4.38, versiones 10.0.0.beta2 hasta 10.0.1 y versiones 11.0.0.beta2 hasta 11.0.1, si un usuario usa un directorio de aplicaciones web que es un enlace simbólico, el contenido del directorio de aplicaciones web se implementa como una aplicación web estática, sin darse cuenta, sirviendo las aplicaciones web en sí y cualquier otra cosa que pueda estar en ese directorio.

If the ${jetty.base} directory or the ${jetty.base}/webapps directory is a symlink the contents of the ${jetty.base}/webapps directory may be deployed as a static web application, exposing the content of the directory for download. The highest threat from this vulnerability is to data confidentiality.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-03-12 CVE Reserved
  • 2021-04-01 CVE Published
  • 2023-11-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (28)
URL Tag Source
https://lists.apache.org/thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r4a66bfbf62281e31bc1345ebecbfd96f35199eecd77bfe4e903e906f%40%3Cissues.ignite.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r4b1fef117bccc7f5fd4c45fd2cabc26838df823fe5ca94bc42a4fd46%40%3Cissues.ignite.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r5b3693da7ecb8a75c0e930b4ca26a5f97aa0207d9dae4aa8cc65fe6b%40%3Cissues.ignite.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r67c4f90658fde875521c949448c54c98517beecdc7f618f902c620ec%40%3Cissues.zookeeper.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r6ac9e263129328c0db9940d72b4a6062e703c58918dd34bd22cdf8dd%40%3Cissues.ignite.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r780c3c210a05c5bf7b4671303f46afc3fe56758e92864e1a5f0590d0%40%3Cjira.kafka.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r787e47297a614b05b99d01b04c8a1d6c0cafb480c9cb7c624a6b8fc3%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/r8a1a332899a1f92c8118b0895b144b27a78e3f25b9d58a34dd5eb084%40%3Cnotifications.zookeeper.apache.org%3E X_refsource_misc
https://lists.apache.org/thread.html/r9974f64723875052e02787b2a5eda689ac5247c71b827d455e5dc9a6%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rbc075a4ac85e7a8e47420b7383f16ffa0af3b792b8423584735f369f%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rbefa055282d52d6b58d29a79fbb0be65ab0a38d25f00bd29eaf5e6fd%40%3Cnotifications.zookeeper.apache.org%3E X_refsource_misc
https://lists.apache.org/thread.html/rd0471252aeb3384c3cfa6d131374646d4641b80dd313e7b476c47a9c%40%3Cissues.solr.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rd7c8fb305a8637480dc943ba08424c8992dccad018cd1405eb2afe0e%40%3Cdev.ignite.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rddbb4f8d5db23265bb63d14ef4b3723b438abc1589f877db11d35450%40%3Cissues.zookeeper.apache.org%3E Mailing List
https://lists.apache.org/thread.html/rf36f1114e84a3379b20587063686148e2d5a39abc0b8a66ff2a9087a%40%3Cissues.zookeeper.apache.org%3E Mailing List
https://security.netapp.com/advisory/ntap-20210611-0006 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Not Applicable
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
>= 9.4.32 < 9.4.39
Search vendor "Eclipse" for product "Jetty" and version " >= 9.4.32 < 9.4.39"
-
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
10.0.0
Search vendor "Eclipse" for product "Jetty" and version "10.0.0"
beta2
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
10.0.1
Search vendor "Eclipse" for product "Jetty" and version "10.0.1"
-
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
11.0.0
Search vendor "Eclipse" for product "Jetty" and version "11.0.0"
-
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
11.0.0
Search vendor "Eclipse" for product "Jetty" and version "11.0.0"
beta2
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
11.0.0
Search vendor "Eclipse" for product "Jetty" and version "11.0.0"
beta3
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
11.0.1
Search vendor "Eclipse" for product "Jetty" and version "11.0.1"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
32
Search vendor "Fedoraproject" for product "Fedora" and version "32"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
33
Search vendor "Fedoraproject" for product "Fedora" and version "33"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
34
Search vendor "Fedoraproject" for product "Fedora" and version "34"
-
Affected
Apache
Search vendor "Apache"
Ignite
Search vendor "Apache" for product "Ignite"
< 2.1.1
Search vendor "Apache" for product "Ignite" and version " < 2.1.1"
-
Affected
Apache
Search vendor "Apache"
Solr
Search vendor "Apache" for product "Solr"
8.8.1
Search vendor "Apache" for product "Solr" and version "8.8.1"
-
Affected
Netapp
Search vendor "Netapp"
Cloud Manager
Search vendor "Netapp" for product "Cloud Manager"
--
Affected
Netapp
Search vendor "Netapp"
E-series Performance Analyzer
Search vendor "Netapp" for product "E-series Performance Analyzer"
--
Affected
Netapp
Search vendor "Netapp"
E-series Santricity Os Controller
Search vendor "Netapp" for product "E-series Santricity Os Controller"
>= 11.0.0 <= 11.70.1
Search vendor "Netapp" for product "E-series Santricity Os Controller" and version " >= 11.0.0 <= 11.70.1"
-
Affected
Netapp
Search vendor "Netapp"
E-series Santricity Web Services
Search vendor "Netapp" for product "E-series Santricity Web Services"
-web_services_proxy
Affected
Netapp
Search vendor "Netapp"
Element Plug-in For Vcenter Server
Search vendor "Netapp" for product "Element Plug-in For Vcenter Server"
--
Affected
Netapp
Search vendor "Netapp"
Santricity Cloud Connector
Search vendor "Netapp" for product "Santricity Cloud Connector"
--
Affected
Netapp
Search vendor "Netapp"
Snapcenter
Search vendor "Netapp" for product "Snapcenter"
--
Affected
Netapp
Search vendor "Netapp"
Snapcenter Plug-in
Search vendor "Netapp" for product "Snapcenter Plug-in"
-vmware_vsphere
Affected
Netapp
Search vendor "Netapp"
Storage Replication Adapter For Clustered Data Ontap
Search vendor "Netapp" for product "Storage Replication Adapter For Clustered Data Ontap"
>= 9.6
Search vendor "Netapp" for product "Storage Replication Adapter For Clustered Data Ontap" and version " >= 9.6"
vmware_vsphere
Affected
Netapp
Search vendor "Netapp"
Vasa Provider For Clustered Data Ontap
Search vendor "Netapp" for product "Vasa Provider For Clustered Data Ontap"
>= 9.6
Search vendor "Netapp" for product "Vasa Provider For Clustered Data Ontap" and version " >= 9.6"
-
Affected
Netapp
Search vendor "Netapp"
Virtual Storage Console
Search vendor "Netapp" for product "Virtual Storage Console"
>= 9.6
Search vendor "Netapp" for product "Virtual Storage Console" and version " >= 9.6"
vmware_vsphere
Affected
Oracle
Search vendor "Oracle"
Autovue For Agile Product Lifecycle Management
Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management"
21.0.2
Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management" and version "21.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
20.1
Search vendor "Oracle" for product "Banking Apis" and version "20.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
21.1
Search vendor "Oracle" for product "Banking Apis" and version "21.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
20.1
Search vendor "Oracle" for product "Banking Digital Experience" and version "20.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
21.1
Search vendor "Oracle" for product "Banking Digital Experience" and version "21.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Element Manager
Search vendor "Oracle" for product "Communications Element Manager"
8.2.2
Search vendor "Oracle" for product "Communications Element Manager" and version "8.2.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Services Gatekeeper
Search vendor "Oracle" for product "Communications Services Gatekeeper"
7.0
Search vendor "Oracle" for product "Communications Services Gatekeeper" and version "7.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Session Report Manager
Search vendor "Oracle" for product "Communications Session Report Manager"
>= 8.0.0 <= 8.2.4.0
Search vendor "Oracle" for product "Communications Session Report Manager" and version " >= 8.0.0 <= 8.2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Session Route Manager
Search vendor "Oracle" for product "Communications Session Route Manager"
>= 8.0.0 <= 8.2.4.0
Search vendor "Oracle" for product "Communications Session Route Manager" and version " >= 8.0.0 <= 8.2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Siebel Core - Automation
Search vendor "Oracle" for product "Siebel Core - Automation"
<= 21.9
Search vendor "Oracle" for product "Siebel Core - Automation" and version " <= 21.9"
-
Affected