First published: Wed May 05 2021(Updated: )
Jetty is a 100% Java HTTP Server and Servlet Container.<br>The following packages have been upgraded to a later upstream version: rh-eclipse-jetty (9.4.40).<br>Security Fix(es):<br><li> jetty: Symlink directory exposes webapp directory contents (CVE-2021-28163)</li> <li> jetty: Ambiguous paths can access WEB-INF (CVE-2021-28164)</li> <li> jetty: Resource exhaustion when receiving an invalid large TLS frame (CVE-2021-28165)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-eclipse-jetty | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-client | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-continuation | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-http | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-io | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-jaas | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-javadoc | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-jmx | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-security | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-server | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-servlet | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-util | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-util-ajax | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-webapp | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
redhat/rh-eclipse-jetty-xml | <9.4.40-1.1.el7_9 | 9.4.40-1.1.el7_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:1509 is considered to be critical due to potential security risks associated with symlink exposure and other vulnerabilities.
To fix RHSA-2021:1509, upgrade to the patched version of the affected packages, specifically rh-eclipse-jetty version 9.4.40-1.1.el7_9.
RHSA-2021:1509 addresses vulnerabilities including CVE-2021-28163, which involves symlink directory exposure affecting web application contents.
Affected packages in RHSA-2021:1509 include rh-eclipse-jetty and several related components such as rh-eclipse-jetty-client and rh-eclipse-jetty-server.
Yes, applying RHSA-2021:1509 is recommended for all users of the affected packages to ensure protection against identified vulnerabilities.