CVE-2018-12538

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
eclipseCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
eclipsejetty
9.4.0 ≤
𝑥
≤ 9.4.8
netappe-series_santricity_management_plug-ins
-
netappe-series_santricity_os_controller
11.0 ≤
𝑥
≤ 11.40
netappe-series_santricity_web_services_proxy
-
netappelement_software
-
netapphyper_converged_infrastructure
-
netapponcommand_system_manager
3.0.0 ≤
𝑥
≤ 3.1.3
netapponcommand_unified_manager
-
netappsantricity_cloud_connector
-
netappsnap_creator_framework
-
netappsnapcenter
-
netappsnapmanager
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty9
bullseye (security)
9.4.50-4+deb11u2
fixed
bullseye
9.4.50-4+deb11u2
fixed
bookworm
9.4.50-4+deb12u3
fixed
bookworm (security)
9.4.50-4+deb12u3
fixed
sid
9.4.56-1
fixed
trixie
9.4.56-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty
bionic
dne
artful
dne
xenial
not-affected
trusty
not-affected
jetty9
bionic
not-affected
artful
ignored
xenial
not-affected
trusty
dne