CVE-2021-28163

Description

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

Risk Information

Base Score
2.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.154

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-28163 are fixed in Eclipse-jetty-deploy 9.4.39Windows
Vulnerabilities CVE-2021-28163 are fixed in Eclipse-jetty-deploy 10.0.2Windows
Vulnerabilities CVE-2021-28163 are fixed in Eclipse-jetty-deploy 11.0.2Windows
Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
Vulnerabilities CVE-2021-28163 are fixed in Eclipse-jetty-deploy for Linux 9.4.39Linux
Vulnerabilities CVE-2021-28163 are fixed in Eclipse-jetty-deploy for Linux 10.0.2Linux
Vulnerabilities CVE-2021-28163 are fixed in Eclipse-jetty-deploy for Linux 11.0.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234