Information disclosure in Jetty - CVE-2021-28163

 

Information disclosure in Jetty - CVE-2021-28163

Published: April 1, 2021


Vulnerability identifier: #VU51878
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28163
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. If the ${jetty.base} directory or the ${jetty.base}/webapps directory is a symlink, the contents of the ${jetty.base}/webapps directory may be deployed as a static web application, exposing the content of the directory for download.


Affected software

Jetty
Red Hat Developer Tools
Sterling Connect:Direct Browser User Interface
Rational Change
Cloudera Data Platform Private Cloud Base for IBM
AMQ Streams
AMQ Broker
Fuse
IBM Analytic Accelerator Framework for Communication Service Providers
Red Hat OpenShift Container Platform
IBM Qradar SIEM
Rational Performance Tester
IBM Customer and Network Analytics for Communications Service Providers and Datasets
Netcool Operations Insight
Red Hat Integration Camel-K
IBM MaaS360 Mobile Enterprise Gateway
Dell NetWorker Virtual Edition
SUSE Linux Enterprise Module for Development Tools
Fedora
runc (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
jenkins (Red Hat package)
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jetty
rh-eclipse-jetty (Red Hat package)
jetty-util-ajax
jetty-util
jetty-servlet
jetty-server
jetty-security
jetty-io
jetty-http
openstack-ironic (Red Hat package)
Dell EMC Storage Monitoring and Reporting (SMR)
IBM InfoSphere Information Server

How to mitigate CVE-2021-28163

Install updates from vendor's website.

Jetty - addressed in versions 9.4.39.v20210325, 10.0.2, 11.0.2
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-32
AMQ Streams - addressed in versions 1.6.4, 1.8.0
IBM Analytic Accelerator Framework for Communication Service Providers - update to 3.6.0.12.0
Red Hat OpenShift Container Platform - addressed in versions 4.7.11, 4.7.12
Rational Change - update to 5.3.2.5
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
AMQ Broker - addressed in versions 7.8.2, 7.9.0
IBM Customer and Network Analytics for Communications Service Providers and Datasets - update to 9.6.0.12.3
runc (Red Hat package) - addressed in versions 1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8
Netcool Operations Insight - update to 1.6.7
Red Hat Integration Camel-K - update to 1.8
cri-tools (Red Hat package) - addressed in versions 1.20.0-2.el7, 1.20.0-2.el8
cri-o (Red Hat package) - addressed in versions 1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8
ignition (Red Hat package) - update to 2.9.0-3.rhaos4.7.git1d56dc8.el8
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
jenkins (Red Hat package) - update to 2.277.3.1620393611-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.6.0.0
openshift-ansible (Red Hat package) - update to 4.7.0-202105111743.p0.git.e1b19c2.el7
openshift-kuryr (Red Hat package) - update to 4.7.0-202105111743.p0.git.36c2cdd.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.7.0-202105111743.p0.git.39cfc66.el8
openshift (Red Hat package) - addressed in versions 4.7.0-202105111743.p0.git.75370d3.el7, 4.7.0-202105111743.p0.git.75370d3.el8
openshift-clients (Red Hat package) - addressed in versions 4.7.0-202105111743.p0.git.95881af.el7, 4.7.0-202105111743.p0.git.95881af.el8
Fuse - update to 7.10.0
jetty - addressed in versions 9.4.40-1.fc32, 9.4.40-1.fc33, 9.4.40-1.fc34
rh-eclipse-jetty (Red Hat package) - update to 9.4.40-1.1.el7_9
jetty-util-ajax - update to 9.4.42-3.9.1
jetty-util - update to 9.4.42-3.9.1
jetty-servlet - update to 9.4.42-3.9.1
jetty-server - update to 9.4.42-3.9.1
jetty-security - update to 9.4.42-3.9.1
jetty-io - update to 9.4.42-3.9.1
jetty-http - update to 9.4.42-3.9.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
openstack-ironic (Red Hat package) - update to 16.0.4-0.20210510131210.6787142.el8
Dell NetWorker Virtual Edition - addressed in versions 19.8.0.4, 19.9.0.2

External References

Related Security Bulletins