QID 980069

QID 980069: Java (maven) Security Update for org.mortbay.jetty:jetty-webapp (GHSA-g3wg-6mcf-8jj6)

Security update has been released for org.eclipse.jetty:jetty-webapp,org.mortbay.jetty:jetty-webapp to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.

Additionally, any user code uses of [WebAppContext::getTempDirectory](https://www.eclipse.org/jetty/javadoc/9.4.31.v20200723/org/eclipse/jetty/webapp/WebAppContext.html#getTempDirectory()) would similarly be vulnerable.

Additionally, any user application code using the `ServletContext` attribute for the tempdir will also be impacted.
See: https://javaee.github.io/javaee-spec/javadocs/javax/servlet/ServletContext.html#TEMPDIR

For example:
```java
import java.io.File;
import java.io.IOException;
import javax.servlet.ServletContext;
import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

public class ExampleServlet extends HttpServlet {
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
File tempDir = (File)getServletContext().getAttribute(ServletContext.TEMPDIR); // Potentially compromised
// do something with that temp dir
}
}
```

Example: The JSP library itself will use the container temp directory for compiling the JSP source into Java classes before executing them.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Fixes were applied to the 9.4.x branch with:
    - https://github.com/eclipse/jetty.project/commit/53e0e0e9b25a6309bf24ee3b10984f4145701edb
    - https://github.com/eclipse/jetty.project/commit/9ad6beb80543b392c91653f6bfce233fc75b9d5f

    These will be included in releases: 9.4.33, 10.0.0.beta3, 11.0.0.beta3Workaround:
    A work around is to set a temporary directory, either for the server or the context, to a directory outside of the shared temporary file system.
    For recent releases, a temporary directory can be created simple by creating a directory called `work` in the ${jetty.base} directory (the parent directory of the `webapps` directory).
    Alternately the java temporary directory can be set with the System Property `java.io.tmpdir`. A more detailed description of how jetty selects a temporary directory is below.

    The Jetty search order for finding a temporary directory is as follows:

    1. If the [`WebAppContext` has a temp directory specified](https://www.eclipse.org/jetty/javadoc/current/org/eclipse/jetty/webapp/WebAppContext.html#setTempDirectory(java.io.File)), use it.
    2. If the `ServletContext` has the `javax.servlet.context.tempdir` attribute set, and if directory exists, use it.
    3. If a `${jetty.base}/work` directory exists, use it (since Jetty 9.1)
    4. If a `ServletContext` has the `org.eclipse.jetty.webapp.basetempdir` attribute set, and if the directory exists, use it.
    5. Use `System.getProperty("java.io.tmpdir")` and use it.

    Jetty will end traversal at the first successful step.
    To mitigate this vulnerability the directory must be set to one that is not writable by an attacker. To avoid information leakage, the directory should also not be readable by an attacker.
    Vendor References

    CVEs related to QID 980069

    Software Advisories
    Advisory ID Software Component Link
    GHSA-g3wg-6mcf-8jj6 org.eclipse.jetty:jetty-webapp URL Logo github.com/advisories/GHSA-g3wg-6mcf-8jj6
    GHSA-g3wg-6mcf-8jj6 org.mortbay.jetty:jetty-webapp URL Logo github.com/advisories/GHSA-g3wg-6mcf-8jj6