In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "34"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
}{
"versions": [
{
"introduced": "9.4.32"
},
{
"fixed": "9.4.39"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.1"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.1.1"
}
]
},
{
"events": [
{
"introduced": "11.0.0"
},
{
"last_affected": "11.70.1"
}
]
},
{
"events": [
{
"introduced": "9.6"
}
]
},
{
"events": [
{
"introduced": "9.6"
}
]
},
{
"events": [
{
"introduced": "9.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2.2"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.9"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28163.json"