Launch Week Day 1: Announcing Security Design Review
LOW 2.7 Maven

Directory exposure in jetty

GHSA-j6qj-j888-vvgq · BIT-solr-2021-28163 · CVE-2021-28163

Published · Modified

Description

Impact

If the ${jetty.base} directory or the ${jetty.base}/webapps directory is a symlink (soft link in Linux), the contents of the ${jetty.base}/webapps directory may be deployed as a static web application, exposing the content of the directory for download.

For example, the problem manifests in the following ${jetty.base}:

demo-base/
├── etc
├── lib
├── resources
├── start.d
├── deploy
│   └── async-rest.war
└── webapps -> deploy

Workarounds

Do not use a symlink

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes