SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34428

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager.

LOW 3.5EPSS 0.96%

Does this matter?

Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS 3.1
3.5 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.96% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-613
Affected
eclipse/jetty · debian/debian linux · netapp/active iq unified manager · netapp/e-series santricity os controller · netapp/e-series santricity web services · netapp/element plug-in for vcenter server · netapp/santricity cloud connector · netapp/snap creator framework · netapp/snapmanager · oracle/autovue for agile product lifecycle management · oracle/communications element manager · oracle/communications services gatekeeper · oracle/communications session report manager · oracle/communications session route manager · oracle/rest data services · oracle/siebel core - automation
Source
emo@eclipse.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.