Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2021-28163

CVE information

Published

3 years ago

Last Modified

5 months ago

CVSSv2.0 Severity

Medium

CVSSv3.1 Severity

Low

Impact Analysis

Description

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory..

CVSSv2.0 Score

Severity
Medium
Base Score
4/10
Exploit Score
8/10
Access Vector
Network
Access Complexity
Low
Authentication Required
Single
Impact Score
2.9/10
Confidentiality Impact
Partial
Availability Impact
None
Integrity Impact
None

CVSSv3.1 Score

Severity
Low
Base Score
2.7/10
Exploit Score
1.2/10
Access Vector
Network
Access Complexity
Low
Privileges Required
High
Impact Score
1.4/10
Confidentiality Impact
Low
Availability Impact
None
Integrity Impact
None
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:eclipse:jetty:11.0.0:beta2:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:eclipse:jetty:10.0.0:beta2:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:eclipse:jetty:11.0.0:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:eclipse:jetty:11.0.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:eclipse:jetty:11.0.0:beta3:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:eclipse:jetty:10.0.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
  Yes
9.4.32 9.4.39
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:apache:solr:8.8.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:apache:ignite:*:*:*:*:*:*:*:*
  Yes
- 2.1.1
cpe:2.3:a:netapp:santricity_cloud_connector:-:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:netapp:e-series_santricity_web_services:-:*:*:*:*:
  Yes
- -
cpe:2.3:a:netapp:virtual_storage_console:*:*:*:*:*:vmware_vs
  Yes
9.6 -
cpe:2.3:a:netapp:storage_replication_adapter_for_clustered_d
  Yes
9.6 -
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:*:*:
  Yes
9.6 -
cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:netapp:snapcenter_plug-in:-:*:*:*:*:vmware_vsphere
  Yes
- -
cpe:2.3:a:netapp:element_plug-in_for_vcenter_server:-:*:*:*:
  Yes
- -
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*
  Yes
11.0.0 -
cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:
  Yes
- -
cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_managem
  Yes
- -
cpe:2.3:a:oracle:siebel_core_-_automation:*:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_session_report_manager:*:*:*
  Yes
8.0.0 -
cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:
  Yes
8.0.0 -
cpe:2.3:a:oracle:communications_element_manager:8.2.2:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
  Yes
- -

References