Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-34428

Опубликовано: 22 июн. 2021
Источник: debian
EPSS Низкий

Описание

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jetty9fixed9.4.39-2package
jetty9not-affectedstretchpackage
jetty8removedpackage
jettyremovedpackage

Примечания

  • https://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6

  • https://github.com/eclipse/jetty.project/issues/6277

  • https://github.com/eclipse/jetty.project/commit/087f486b4461746b4ded45833887b3ccb136ee85 (jetty-9.4.x)

EPSS

Процентиль: 71%
0.00669
Низкий

Связанные уязвимости

CVSS3: 2.9
ubuntu
больше 4 лет назад

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS3: 3.5
redhat
больше 4 лет назад

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS3: 2.9
nvd
больше 4 лет назад

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS3: 3.5
github
больше 4 лет назад

SessionListener can prevent a session from being invalidated breaking logout

CVSS3: 2.9
fstec
больше 4 лет назад

Уязвимость метода SessionListener#sessionDestroyed() контейнера сервлетов Eclipse Jetty, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 71%
0.00669
Низкий