Information disclosure in Jetty - CVE-2021-28163
Published: April 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. If the ${jetty.base} directory or the ${jetty.base}/webapps directory is a symlink, the contents of the ${jetty.base}/webapps directory may be deployed as a static web application, exposing the content of the directory for download.
Affected software
Red Hat Developer Tools
Sterling Connect:Direct Browser User Interface
Rational Change
Cloudera Data Platform Private Cloud Base for IBM
AMQ Streams
AMQ Broker
Fuse
IBM Analytic Accelerator Framework for Communication Service Providers
Red Hat OpenShift Container Platform
IBM Qradar SIEM
Rational Performance Tester
IBM Customer and Network Analytics for Communications Service Providers and Datasets
Netcool Operations Insight
Red Hat Integration Camel-K
IBM MaaS360 Mobile Enterprise Gateway
Dell NetWorker Virtual Edition
SUSE Linux Enterprise Module for Development Tools
Fedora
runc (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
jenkins (Red Hat package)
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jetty
rh-eclipse-jetty (Red Hat package)
jetty-util-ajax
jetty-util
jetty-servlet
jetty-server
jetty-security
jetty-io
jetty-http
openstack-ironic (Red Hat package)
Dell EMC Storage Monitoring and Reporting (SMR)
IBM InfoSphere Information Server
How to mitigate CVE-2021-28163
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-32
AMQ Streams - addressed in versions 1.6.4, 1.8.0
IBM Analytic Accelerator Framework for Communication Service Providers - update to 3.6.0.12.0
Red Hat OpenShift Container Platform - addressed in versions 4.7.11, 4.7.12
Rational Change - update to 5.3.2.5
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
AMQ Broker - addressed in versions 7.8.2, 7.9.0
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 9.6.0.12.3
runc (Red Hat package) - addressed in versions 1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8
Netcool Operations Insight - update to 1.6.7
Red Hat Integration Camel-K - update to 1.8
cri-tools (Red Hat package) - addressed in versions 1.20.0-2.el7, 1.20.0-2.el8
cri-o (Red Hat package) - addressed in versions 1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8
ignition (Red Hat package) - update to 2.9.0-3.rhaos4.7.git1d56dc8.el8
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
jenkins (Red Hat package) - update to 2.277.3.1620393611-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
openshift-ansible (Red Hat package) - update to 4.7.0-202105111743.p0.git.e1b19c2.el7
openshift-kuryr (Red Hat package) - update to 4.7.0-202105111743.p0.git.36c2cdd.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.7.0-202105111743.p0.git.39cfc66.el8
openshift (Red Hat package) - addressed in versions 4.7.0-202105111743.p0.git.75370d3.el7, 4.7.0-202105111743.p0.git.75370d3.el8
openshift-clients (Red Hat package) - addressed in versions 4.7.0-202105111743.p0.git.95881af.el7, 4.7.0-202105111743.p0.git.95881af.el8
Fuse - update to 7.10.0
jetty - addressed in versions 9.4.40-1.fc32, 9.4.40-1.fc33, 9.4.40-1.fc34
rh-eclipse-jetty (Red Hat package) - update to 9.4.40-1.1.el7_9
jetty-util-ajax - update to 9.4.42-3.9.1
jetty-util - update to 9.4.42-3.9.1
jetty-servlet - update to 9.4.42-3.9.1
jetty-server - update to 9.4.42-3.9.1
jetty-security - update to 9.4.42-3.9.1
jetty-io - update to 9.4.42-3.9.1
jetty-http - update to 9.4.42-3.9.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
openstack-ironic (Red Hat package) - update to 16.0.4-0.20210510131210.6787142.el8
Dell NetWorker Virtual Edition - addressed in versions 19.8.0.4, 19.9.0.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Jetty
- Red Hat Developer Tools update for rh-eclipse-jetty
- Red Hat AMQ Streams update for jetty
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM MaaS360 Mobile Enterprise Gateway
- SUSE update for jetty-minimal
- Multiple vulnerabilities in IBM Sterling Connect:Direct Browser User Interface
- Multiple vulnerabilities in IBM Rational Performance Tester
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in IBM Rational Change
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Analytic Accelerator Framework for Communication Service Providers & IBM Customer and Network Analytics
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Dell NetWorker Virtual Edition
- Multiple vulnerabilities in IBM Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Multiple vulnerabilities in Fuse 7.10
- Fedora 34 update for jetty
- Fedora 33 update for jetty
- Fedora 32 update for jetty