First published: Thu Apr 01 2021(Updated: )
Eclipse Jetty could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw when the ${jetty.base} directory or the ${jetty.base}/webapps directory is a symlink. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain webapp directory contents information, and use this information to launch further attacks against the affected system.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-eclipse-jetty | <0:9.4.40-1.1.el7_9 | 0:9.4.40-1.1.el7_9 |
redhat/jenkins | <0:2.277.3.1620393611-1.el8 | 0:2.277.3.1620393611-1.el8 |
redhat/runc | <0:1.0.0-95.rhaos4.8.gitcd80260.el8 | 0:1.0.0-95.rhaos4.8.gitcd80260.el8 |
redhat/jetty | <9.4.39 | 9.4.39 |
redhat/jetty | <10.0.2 | 10.0.2 |
redhat/jetty | <11.0.2 | 11.0.2 |
Eclipse Jetty | >=9.4.32<9.4.39 | |
Eclipse Jetty | =10.0.0-beta2 | |
Eclipse Jetty | =10.0.1 | |
Eclipse Jetty | =11.0.0 | |
Eclipse Jetty | =11.0.0-beta2 | |
Eclipse Jetty | =11.0.0-beta3 | |
Eclipse Jetty | =11.0.1 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Apache Ignite | <2.1.1 | |
Apache Solr | =8.8.1 | |
NetApp Cloud Manager | ||
Netapp E-series Performance Analyzer | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
Netapp E-series Santricity Web Services Web Services Proxy | ||
Netapp Element Plug-in For Vcenter Server | ||
Netapp Santricity Cloud Connector | ||
Netapp Snapcenter | ||
Netapp Snapcenter Plug-in Vmware Vsphere | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | >=9.6 | |
Netapp Vasa Provider For Clustered Data Ontap | >=9.6 | |
Netapp Virtual Storage Console Vmware Vsphere | >=9.6 | |
Oracle Autovue For Agile Product Lifecycle Management | =21.0.2 | |
Oracle Banking Apis | =20.1 | |
Oracle Banking Apis | =21.1 | |
Oracle Banking Digital Experience | =20.1 | |
Oracle Banking Digital Experience | =21.1 | |
Oracle Communications Element Manager | =8.2.2 | |
Oracle Communications Services Gatekeeper | =7.0 | |
Oracle Communications Session Report Manager | >=8.0.0<=8.2.4.0 | |
Oracle Communications Session Route Manager | >=8.0.0<=8.2.4.0 | |
Oracle Siebel Core - Automation | <=21.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-28163 is a vulnerability in Eclipse Jetty that allows a remote authenticated attacker to obtain sensitive information.
CVE-2021-28163 occurs when the ${jetty.base} directory or the ${jetty.base}/webapps directory is a symlink. By sending a specially-crafted request, an attacker can exploit this vulnerability to obtain webapp directory information.
The severity of CVE-2021-28163 is medium, with a severity value of 2.7.
Jetty versions 9.4.32 to 9.4.39, 10.0.0-beta2 to 10.0.2, and 11.0.0-beta2 to 11.0.2 are affected by CVE-2021-28163.
To fix CVE-2021-28163, it is recommended to update Jetty to version 9.4.39, 10.0.2, or 11.0.2.