Vulnerability   
Search   
    Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.146165
Category:Web Servers
Title:Eclipse Jetty Session Vulnerability (GHSA-m6cp-vxjx-65j6) - Windows
Summary:Eclipse Jetty is prone to a vulnerability in the session; management.
Description:Summary:
Eclipse Jetty is prone to a vulnerability in the session
management.

Vulnerability Insight:
If an exception is thrown from the SessionListener#sessionDestroyed()
method, then the session ID is not invalidated in the session ID manager. On deployments with
clustered sessions and multiple contexts this can result in a session not being invalidated. This
can result in an application used on a shared computer being left logged in.

Affected Software/OS:
Eclipse Jetty version 9.4.40.v20210413 and prior, 10.x through
10.0.2 and 11.x through 11.0.2.

Solution:
Update to version 9.4.41.v20210516, 10.0.3, 11.0.3 or later.

CVSS Score:
3.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-34428
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.