Tracker / CVE-2021-28163
CVE-2021-28163
Low 2.7
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
Affected products and versions
| apache | ignite · … → 2.1.1 |
|---|---|
| apache | solr |
| eclipse | jetty |
| eclipse | jetty · 9.4.32 → 9.4.39 |
| fedoraproject | fedora |
| netapp | cloud_manager |
| netapp | e-series_performance_analyzer |
| netapp | e-series_santricity_os_controller · 11.0.0 → 11.70.1 |
| netapp | e-series_santricity_web_services |
| netapp | element_plug-in_for_vcenter_server |
| netapp | santricity_cloud_connector |
| netapp | snapcenter |
| netapp | snapcenter_plug-in |
| netapp | storage_replication_adapter_for_clustered_data_ontap · 9.6 → … |
| netapp | vasa_provider_for_clustered_data_ontap · 9.6 → … |
| netapp | virtual_storage_console · 9.6 → … |
| oracle | autovue_for_agile_product_lifecycle_management |
| oracle | banking_apis |
| oracle | banking_digital_experience |
| oracle | communications_element_manager |
| oracle | communications_services_gatekeeper |
| oracle | communications_session_report_manager · 8.0.0 → 8.2.4.0 |
| oracle | communications_session_route_manager · 8.0.0 → 8.2.4.0 |
| oracle | siebel_core_-_automation · … → 21.9 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.