Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-34428

Опубликовано: 22 июн. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 3.6
CVSS3: 2.9

Описание

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

needs-triage

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

needs-triage

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

9.4.57-1
esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

9.4.45-1
esm-apps/noble

not-affected

9.4.53-1
esm-apps/resolute

not-affected

9.4.57-1
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

Показывать по

EPSS

Процентиль: 59%
0.00963
Низкий

3.6 Low

CVSS2

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
redhat
около 5 лет назад

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS3: 2.9
nvd
около 5 лет назад

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS3: 2.9
debian
около 5 лет назад

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exce ...

CVSS3: 3.5
github
около 5 лет назад

SessionListener can prevent a session from being invalidated breaking logout

CVSS3: 2.9
fstec
около 5 лет назад

Уязвимость метода SessionListener#sessionDestroyed() контейнера сервлетов Eclipse Jetty, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 59%
0.00963
Низкий

3.6 Low

CVSS2

2.9 Low

CVSS3