CVE-2021-34428

Aliases:GHSA-m6cp-vxjx-65j6DEBIAN-CVE-2021-34428CGA-25v7-w33g-2437CGA-28mm-6jcq-w5jwCGA-342x-jmvh-pvxfCGA-5469-mrhr-pq3hCGA-62hw-ppcq-3rp2CGA-6w86-75m4-5vvvCGA-7jc2-hv3x-p9prCGA-7w92-cx32-282pCGA-897h-qpmp-6vhmCGA-h33r-g4jx-662qCGA-j7rg-h64p-phrcCGA-jcwx-74qg-jc68CGA-mpx2-p77q-mjm5CGA-p2j7-3hfm-qxwpCGA-p9h2-q2qp-7rp4CGA-qhfv-cx6v-r5qpCGA-qhpp-h8qh-gw96CGA-r685-f3fx-r3pmCGA-x2h9-vj4v-fx58CGA-xrhv-2487-x4xx
Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 22 Jun 2021, 14:45
Last modified:04 Aug 2024, 00:12

Vulnerability Summary

Overall Risk (default)
low
15/100
CVSS Score
3.6 LOW
v2.0 (nvd)
EPSS Score
0.96% LOW
1% probability +0.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Jun 2021, 14:45
Published
Vulnerability first disclosed
04 Aug 2024, 00:12
Last Modified
Vulnerability information updated

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS Metrics

  • v3.1LOWScore: 2.9CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  • v3.1LOWScore: 3.5CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v2.0LOWScore: 3.6AV:L/AC:L/Au:N/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.96% Percentile: 60%

Techniques & Countermeasures

  • CWE-613Insufficient Session Expiration

    According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Affected Systems

  • chainguardhadoop-fips-3.3.6

    all

  • chainguardhadoop-fips-3.4.2

    all

  • chainguardhadoop-fips-3.5

    all

  • debianjetty9

    < 9.4.39-2 | < 9.4.39-2 | < 9.4.39-2 | < 9.4.39-2

  • debiandebian_linux

    10.0

  • eclipsejetty

    ≤ 9.4.40 | ≥ 10.0.0, ≤ 10.0.2 | ≥ 11.0.0, ≤ 11.0.2

  • org.eclipse.jettyjetty-server

    < 9.4.41 | ≥ 10.0.0, < 10.0.3 | ≥ 11.0.0, < 11.0.3

  • netappactive_iq_unified_manager

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.1

  • netappe-series_santricity_web_services

    na

  • netappelement_plug-in_for_vcenter_server

    na

  • netappsantricity_cloud_connector

    na

  • netappsnap_creator_framework

    na

  • netappsnapmanager

    na

  • oracleautovue_for_agile_product_lifecycle_management

    21.0.2

  • oraclecommunications_element_manager

    8.2.2

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_report_manager

    ≥ 8.0.0.0, ≤ 8.2.4.0

  • oraclecommunications_session_route_manager

    ≥ 8.0.0, ≤ 8.2.4.0

  • oraclerest_data_services

    < 21.3

  • oraclesiebel_core_-_automation

    ≤ 21.9

  • the eclipse foundationeclipse jetty

    ≥ 9.0.0, < unspecified | ≥ unspecified, ≤ 9.4.40 | ≥ 10.0.0, < unspecified | ≥ unspecified, ≤ 10.0.2 | ≥ 11.0.0, < unspecified | ≥ unspecified, ≤ 11.0.2

References (22)