CVE-2021-28163

Aliases:GHSA-j6qj-j888-vvgqBIT-solr-2021-28163
Modified
Published: 01 Apr 2021, 14:20
Last modified:03 Aug 2024, 21:40

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
0.15% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

01 Apr 2021, 14:20
Published
Vulnerability first disclosed
03 Aug 2024, 21:40
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

CVSS Metrics

  • v3.1LOWScore: 2.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.15% Percentile: 36%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • apacheignite

    < 2.1.1

  • UnknownSolr

    8.8.1

  • eclipsejetty

    ≥ 9.4.32, < 9.4.39 | 10.0.0:beta2 | 10.0.1 | 11.0.0 | 11.0.0:beta2 | 11.0.0:beta3 | 11.0.1

  • fedoraprojectfedora

    32 | 33 | 34

  • org.eclipse.jettyjetty-deploy

    ≥ 9.4.32, < 9.4.39 | ≥ 10.0.0, < 10.0.2 | ≥ 11.0.0, < 11.0.2

  • netappcloud_manager

    na

  • netappe-series_performance_analyzer

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.1

  • netappe-series_santricity_web_services

    na

  • netappelement_plug-in_for_vcenter_server

    na

  • netappsantricity_cloud_connector

    na

  • netappsnapcenter

    na

  • netappsnapcenter_plug-in

    na

  • netappstorage_replication_adapter_for_clustered_data_ontap

    ≥ 9.6

  • netappvasa_provider_for_clustered_data_ontap

    ≥ 9.6

  • netappvirtual_storage_console

    ≥ 9.6

  • oracleautovue_for_agile_product_lifecycle_management

    21.0.2

  • oraclebanking_apis

    20.1 | 21.1

  • oraclebanking_digital_experience

    20.1 | 21.1

  • oraclecommunications_element_manager

    8.2.2

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_report_manager

    ≥ 8.0.0, ≤ 8.2.4.0

  • oraclecommunications_session_route_manager

    ≥ 8.0.0, ≤ 8.2.4.0

  • oraclesiebel_core_-_automation

    ≤ 21.9

  • the eclipse foundationeclipse jetty

    ≥ 9.4.32, < unspecified | ≥ unspecified, ≤ 9.4.38 | ≥ 10.0.0.beta2, < unspecified | ≥ unspecified, ≤ 10.0.1 | ≥ 11.0.0.beta2, < unspecified | ≥ unspecified, ≤ 11.0.1

References (50)