CVE-2021-34428

Aliases:GHSA-m6cp-vxjx-65j6
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 22 Jun 2021, 14:45
Last modified:04 Aug 2024, 00:12

Vulnerability Summary

Overall Risk (default)
low
14/100
CVSS Score
3.6 LOW
v2.0 (nvd)
EPSS Score
0.29% LOW
0% probability -0.38%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Jun 2021, 14:45
Published
Vulnerability first disclosed
04 Aug 2024, 00:12
Last Modified
Vulnerability information updated

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS Metrics

  • v3.1LOWScore: 2.9CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  • v3.1LOWScore: 3.5CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v2.0LOWScore: 3.6AV:L/AC:L/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.29% Percentile: 53%

Techniques & Countermeasures

  • CWE-613Insufficient Session Expiration

    According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Affected Systems

  • debiandebian_linux

    10.0

  • eclipsejetty

    ≤ 9.4.40 | ≥ 10.0.0, ≤ 10.0.2 | ≥ 11.0.0, ≤ 11.0.2

  • org.eclipse.jettyjetty-server

    < 9.4.41 | ≥ 10.0.0, < 10.0.3 | ≥ 11.0.0, < 11.0.3

  • netappactive_iq_unified_manager

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.1

  • netappe-series_santricity_web_services

    na

  • netappelement_plug-in_for_vcenter_server

    na

  • netappsantricity_cloud_connector

    na

  • netappsnap_creator_framework

    na

  • netappsnapmanager

    na

  • oracleautovue_for_agile_product_lifecycle_management

    21.0.2

  • oraclecommunications_element_manager

    8.2.2

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_report_manager

    ≥ 8.0.0.0, ≤ 8.2.4.0

  • oraclecommunications_session_route_manager

    ≥ 8.0.0, ≤ 8.2.4.0

  • oraclerest_data_services

    < 21.3

  • oraclesiebel_core_-_automation

    ≤ 21.9

  • the eclipse foundationeclipse jetty

    ≥ 9.0.0, < unspecified | ≥ unspecified, ≤ 9.4.40 | ≥ 10.0.0, < unspecified | ≥ unspecified, ≤ 10.0.2 | ≥ 11.0.0, < unspecified | ≥ unspecified, ≤ 11.0.2

References (21)