Bug 1945712 (CVE-2021-28164)
Summary: | CVE-2021-28164 jetty: Ambiguous paths can access WEB-INF | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | abenaiss, aileenc, aos-bugs, ataylor, bibryam, bmontgom, chazlett, dbecker, drieden, eclipse-sig, eparis, eric.wittmann, ggaughan, gmalinko, hbraun, janstey, java-maint, jburrell, jjohnstn, jjoyce, jnethert, jochrist, jokerman, jross, jschluet, jwon, krzysztof.daniel, lhh, lpeer, mburns, mizdebsk, mkolesni, nstielau, pantinor, pbhattac, sclewis, scohen, sd-operator-metering, slinaber, sochotni, sponnaga, swoodman, tflannag, vbobade |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | jetty 9.4.39 | Doc Type: | If docs needed, set a value |
Doc Text: |
In Jetty the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. An attacker can use this vulnerability to reveal sensitive information regarding the implementation of a web application.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-05-06 20:34:03 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1945713, 1952066, 1952067 | ||
Bug Blocks: | 1945716 |
Description
Pedro Sampaio
2021-04-01 17:46:45 UTC
Created jetty tracking bugs for this issue: Affects: fedora-all [bug 1945713] External References: https://github.com/eclipse/jetty.project/security/advisories/GHSA-v7ff-8wcx-gmc5 The issue was introduced with version 9.4.37. Older versions of jetty are not affected. Upstream patch: https://github.com/eclipse/jetty.project/commit/d80c622b005c044e93f585c231b420a29371f6e0 This vulnerability is out of security support scope for the following products: * Red Hat JBoss Fuse 6 * Red Hat JBoss A-MQ 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details. Marking Red Hat Camel K as having a low impact, although Camel K distributes jetty artifacts through camel-jetty, camel-jetty itself is not available for use by the application developer, http functionality is provided by camel-k default runtime, Quarkus. Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Important and Critical flaws. Red Hat CodeReady Studio 12 is not affected by this vulnerability because it does not ship a vulnerable version of jetty. This issue has been addressed in the following products: Red Hat Developer Tools Via RHSA-2021:1509 https://access.redhat.com/errata/RHSA-2021:1509 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-28164 This issue has been addressed in the following products: Red Hat AMQ Streams 1.6.4 Via RHSA-2021:1560 https://access.redhat.com/errata/RHSA-2021:1560 Marking Red Hat Integration Red Hat Integration Service Registry as having a low impact, although Service Registry distributes Jetty as part of Kafka Connect component it is not available in the productised release, meaning jetty is also not available for use by the end application developer. This issue has been addressed in the following products: Red Hat AMQ 7.8.2 Via RHSA-2021:2689 https://access.redhat.com/errata/RHSA-2021:2689 This issue has been addressed in the following products: Red Hat AMQ Streams 1.8.0 Via RHSA-2021:3225 https://access.redhat.com/errata/RHSA-2021:3225 This issue has been addressed in the following products: Red Hat AMQ 7.9.0 Via RHSA-2021:3700 https://access.redhat.com/errata/RHSA-2021:3700 This issue has been addressed in the following products: Red Hat Integration Via RHSA-2021:4767 https://access.redhat.com/errata/RHSA-2021:4767 This issue has been addressed in the following products: Red Hat Fuse 7.10 Via RHSA-2021:5134 https://access.redhat.com/errata/RHSA-2021:5134 This issue has been addressed in the following products: RHAF Camel-K 1.8 Via RHSA-2022:6407 https://access.redhat.com/errata/RHSA-2022:6407 |