Directory exposure in jetty
Package
Affected versions
>= 9.4.32, < 9.4.39
>= 10.0.0, < 10.0.2
>= 11.0.0, < 11.0.2
Patched versions
9.4.39
10.0.2
11.0.2
Description
Published by the National Vulnerability Database
Apr 1, 2021
Reviewed
Apr 2, 2021
Published to the GitHub Advisory Database
Apr 6, 2021
Last updated
Feb 1, 2023
Impact
If the
${jetty.base}
directory or the${jetty.base}/webapps
directory is a symlink (soft link in Linux), the contents of the${jetty.base}/webapps
directory may be deployed as a static web application, exposing the content of the directory for download.For example, the problem manifests in the following
${jetty.base}
:Workarounds
Do not use a symlink
References