[MAVEN:GHSA-MWCX-532G-8PQ3] Access and integrity issue within Eclipse Jetty

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

Package Affected Version
pkg:maven/org.eclipse.jetty/jetty-server >= 9.4.0, <= 9.4.10.v20180503
Package Fixed Version
pkg:maven/org.eclipse.jetty/jetty-server = 9.4.11.v20180605
ID
MAVEN:GHSA-MWCX-532G-8PQ3
Severity
high
URL
https://github.com/advisories/GHSA-mwcx-532g-8pq3
Published
2018-10-16T17:44:11
(6 years ago)
Modified
2023-01-09T05:03:33
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server >= 9.4.0 <= 9.4.10.v20180503
Fixed pkg:maven/org.eclipse.jetty/jetty-server org.eclipse.jetty jetty-server = 9.4.11.v20180605
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...