In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
CVSS Details
- CVSS 3.1 Base Score: 2.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jetty9 | Jul 30, 2024 | Apr 1, 2021 |
| Redhat Openshift | — | Upgrade jenkinsUpgrade runc | May 21, 2021 | Apr 1, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 1, 2021 |
| Suse | — | Upgrade jetty-xmlUpgrade jetty-minimal-javadocUpgrade jetty-continuationUpgrade jetty-serverUpgrade jetty-jmxUpgrade jetty-jndiUpgrade jetty-websocket-servletUpgrade jetty-websocket-apiUpgrade jetty-util-ajaxUpgrade jetty-webappUpgrade jetty-httpUpgrade jetty-jaasUpgrade jetty-ioUpgrade jetty-utilUpgrade jetty-openidUpgrade jetty-javax-websocket-client-implUpgrade jetty-proxyUpgrade jetty-websocket-javadocUpgrade jetty-javax-websocket-server-implUpgrade jetty-plusUpgrade jetty-annotationsUpgrade jetty-websocket-commonUpgrade jetty-servletUpgrade jetty-websocket-serverUpgrade jetty-clientUpgrade jetty-jspUpgrade jetty-securityUpgrade jetty-websocket-client | Jun 19, 2021 | Apr 1, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub