Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12538

Опубликовано: 18 июн. 2018
Источник: redhat
CVSS3: 5.6

Описание

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jetty-eclipseNot affected
Red Hat Enterprise Linux 7jettyNot affected
Red Hat Fuse 7jettyNot affected
Red Hat JBoss Fuse 6jettyNot affected
Red Hat Satellite 5jettyNot affected
Red Hat Software Collectionsrh-java-common-jettyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1595453jetty: HttpSessions access/hijack in the FileSystem's storage for the FileSessionDataStore.

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

CVSS3: 8.8
nvd
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

CVSS3: 8.8
debian
больше 7 лет назад

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional ...

CVSS3: 8.8
github
больше 7 лет назад

Access and integrity issue within Eclipse Jetty

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость реализации класса FileSessionDataStore HTTP-сервера Jetty, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.6 Medium

CVSS3