cbcvebase.
CVE-2018-12538
published 2018-06-22

CVE-2018-12538: In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is…

PriorityP351high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.69%
84.2th percentile
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianjetty9
eclipsejetty9.4.0 – 9.4.8
netappe-series_santricity_os_controller11.0 – 11.40
netapponcommand_system_manager3.0.0 – 3.1.3
the_eclipse_foundationeclipse_jetty>= 9.4.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= unspecified < 9.4.99.4.9

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.