CVE-2021-28163

LOW

NetApp Cloud Manager - Exposure of Sensitive Information via Symlink Webapps Directory

Title source: llm
STIX 2.1

Description

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

References (26)

Core 26
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210611-0006/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Not Applicable, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 2.7
EPSS 0.0015
EPSS Percentile 35.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-59
Status published
Products (32)
apache/ignite < 2.1.1
apache/solr 8.8.1
eclipse/jetty 10.0.0 beta2
eclipse/jetty 10.0.1
eclipse/jetty 11.0.0 (3 CPE variants)
eclipse/jetty 11.0.1
eclipse/jetty 9.4.32 - 9.4.39
fedoraproject/fedora 32
fedoraproject/fedora 33
fedoraproject/fedora 34
... and 22 more
Published Apr 01, 2021
Tracked Since Feb 18, 2026