imPC@ndo IT

Tracker / CVE-2021-28163

CVE-2021-28163

Low 2.7

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

Affected products and versions

apache ignite · … → 2.1.1
apache solr
eclipse jetty
eclipse jetty · 9.4.32 → 9.4.39
fedoraproject fedora
netapp cloud_manager
netapp e-series_performance_analyzer
netapp e-series_santricity_os_controller · 11.0.0 → 11.70.1
netapp e-series_santricity_web_services
netapp element_plug-in_for_vcenter_server
netapp santricity_cloud_connector
netapp snapcenter
netapp snapcenter_plug-in
netapp storage_replication_adapter_for_clustered_data_ontap · 9.6 → …
netapp vasa_provider_for_clustered_data_ontap · 9.6 → …
netapp virtual_storage_console · 9.6 → …
oracle autovue_for_agile_product_lifecycle_management
oracle banking_apis
oracle banking_digital_experience
oracle communications_element_manager
oracle communications_services_gatekeeper
oracle communications_session_report_manager · 8.0.0 → 8.2.4.0
oracle communications_session_route_manager · 8.0.0 → 8.2.4.0
oracle siebel_core_-_automation · … → 21.9

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References