Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwcx-532g-8pq3

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Access and integrity issue within Eclipse Jetty

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

Пакеты

Наименование

org.eclipse.jetty:jetty-server

maven
Затронутые версииВерсия исправления

>= 9.4.0, <= 9.4.10.v20180503

9.4.11.v20180605

EPSS

Процентиль: 66%
0.00515
Низкий

8.8 High

CVSS3

Дефекты

CWE-384
CWE-6

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

CVSS3: 5.6
redhat
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

CVSS3: 8.8
nvd
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

CVSS3: 8.8
debian
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional ...

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость реализации класса FileSessionDataStore HTTP-сервера Jetty, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 66%
0.00515
Низкий

8.8 High

CVSS3

Дефекты

CWE-384
CWE-6