CVE-2021-34428
published 2021-06-22CVE-2021-34428: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID…
PriorityP412low3.5CVSS 3.1
AVPACLPRNUINSUCLILAN
EPSS
0.96%
57.8th percentile
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jetty9 | < jetty9 9.4.39-2 (bookworm) | jetty9 9.4.39-2 (bookworm) |
| eclipse | jetty | <= 9.4.40 | — |
| eclipse | jetty | 10.0.0 – 10.0.2 | — |
| eclipse | jetty | 11.0.0 – 11.0.2 | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.1 | — |
| oracle | autovue_for_agile_product_lifecycle_management | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_services_gatekeeper | — | — |
| oracle | communications_session_report_manager | 8.0.0.0 – 8.2.4.0 | — |
| oracle | communications_session_route_manager | 8.0.0 – 8.2.4.0 | — |
| oracle | rest_data_services | < 21.3 | 21.3 |
| oracle | siebel_core_automation | <= 21.9 | — |
| the_eclipse_foundation | eclipse_jetty | >= 10.0.0 < unspecified | unspecified |
| the_eclipse_foundation | eclipse_jetty | >= 11.0.0 < unspecified | unspecified |
| the_eclipse_foundation | eclipse_jetty | >= 9.0.0 < unspecified | unspecified |
| the_eclipse_foundation | eclipse_jetty | unspecified – 9.4.40 | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv3.5LOW
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
SessionListener can prevent a session from being invalidated breaking logout
osv·2021-06-23
CVE-2021-34428 [LOW] SessionListener can prevent a session from being invalidated breaking logout
SessionListener can prevent a session from being invalidated breaking logout
### Impact
If an exception is thrown from the `SessionListener#sessionDestroyed()` method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
There is no known path for an attacker to induce such an exception to be thrown, thus they must rely on an application to throw such an exception. The OP has also identified that during the call to `sessionDestroyed`, the `getLastAccessedTime()` throws an `IllegalStateException`, which potentially contrary to the servlet spec, so applications calling this method may
GHSA
SessionListener can prevent a session from being invalidated breaking logout
ghsa·2021-06-23
CVE-2021-34428 [LOW] CWE-613 SessionListener can prevent a session from being invalidated breaking logout
SessionListener can prevent a session from being invalidated breaking logout
### Impact
If an exception is thrown from the `SessionListener#sessionDestroyed()` method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
There is no known path for an attacker to induce such an exception to be thrown, thus they must rely on an application to throw such an exception. The OP has also identified that during the call to `sessionDestroyed`, the `getLastAccessedTime()` throws an `IllegalStateException`, which potentially contrary to the servlet spec, so applications calling this method may
OSV
CVE-2021-34428: For Eclipse Jetty versions <= 9
osv·2021-06-22·CVSS 3.5
CVE-2021-34428 [LOW] CVE-2021-34428: For Eclipse Jetty versions <= 9
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Red Hat
jetty: SessionListener can prevent a session from being invalidated breaking logout
vendor_redhat·2021-06-22·CVSS 2.9
CVE-2021-34428 [LOW] CWE-613 jetty: SessionListener can prevent a session from being invalidated breaking logout
jetty: SessionListener can prevent a session from being invalidated breaking logout
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
A flaw was discovered in the jetty-server, where if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts, this could result in a session not being invalidated and a s
Debian
CVE-2021-34428: jetty9 - For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is t...
vendor_debian·2021·CVSS 2.9
CVE-2021-34428 [LOW] CVE-2021-34428: jetty9 - For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is t...
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Scope: local
bookworm: resolved (fixed in 9.4.39-2)
bullseye: resolved (fixed in 9.4.39-2)
forky: resolved (fixed in 9.4.39-2)
sid: resolved (fixed in 9.4.39-2)
trixie: resolved (fixed in 9.4.39-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-34428 jetty: SessionListener can prevent a session from being invalidated breaking logout
bugzilla·2021-06-22·CVSS 3.5
CVE-2021-34428 [LOW] CVE-2021-34428 jetty: SessionListener can prevent a session from being invalidated breaking logout
CVE-2021-34428 jetty: SessionListener can prevent a session from being invalidated breaking logout
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Reference:
https://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6
Discussion:
Created jetty tracking bugs for this issue:
Affects: fedora-all [bug 1974892]
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
* Red
arXiv
Security Review of Ethereum Beacon Clients
arxiv_fulltext·2021-09-23
Security Review of Ethereum Beacon Clients
center
[width=7cm]beacon
empty
1cm
Security Review of Ethereum Beacon Clients
1cm
JP Aumasson -- Taurus, Switzerland -- [email protected],
Denis Kolegov -- Tomsk State University, Russia -- [email protected]
Evangelia Stathopoulou -- University College London, UK -- [email protected]
0.5cm
Version
0.5cm
Supported by the Ethereum Foundation.
center
## Abstract
The beacon chain is the backbone of the Ethereum's evolution
towards a proof-of-stake-based scalable network.
Beacon clients are the applications implementing the services
required to operate the beacon chain, namely validators, beacon
nodes, and slashers.
Security defects in beacon clients could lead to loss of funds,
consensus rules violation, network congestion, and other
inconveniences.
We repo
https://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6https://lists.apache.org/thread.html/r67c4f90658fde875521c949448c54c98517beecdc7f618f902c620ec%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r8a1a332899a1f92c8118b0895b144b27a78e3f25b9d58a34dd5eb084%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rbefa055282d52d6b58d29a79fbb0be65ab0a38d25f00bd29eaf5e6fd%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rddbb4f8d5db23265bb63d14ef4b3723b438abc1589f877db11d35450%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/ref1c161a1621504e673f9197b49e6efe5a33ce3f0e6d8f1f804fc695%40%3Cjira.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rf36f1114e84a3379b20587063686148e2d5a39abc0b8a66ff2a9087a%40%3Cissues.zookeeper.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210813-0003/https://www.debian.org/security/2021/dsa-4949https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6https://lists.apache.org/thread.html/r67c4f90658fde875521c949448c54c98517beecdc7f618f902c620ec%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r8a1a332899a1f92c8118b0895b144b27a78e3f25b9d58a34dd5eb084%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rbefa055282d52d6b58d29a79fbb0be65ab0a38d25f00bd29eaf5e6fd%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/rddbb4f8d5db23265bb63d14ef4b3723b438abc1589f877db11d35450%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/ref1c161a1621504e673f9197b49e6efe5a33ce3f0e6d8f1f804fc695%40%3Cjira.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rf36f1114e84a3379b20587063686148e2d5a39abc0b8a66ff2a9087a%40%3Cissues.zookeeper.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210813-0003/https://www.debian.org/security/2021/dsa-4949https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-22
Published