cbcvebase.
CVE-2021-34428
published 2021-06-22

CVE-2021-34428: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID…

low3.5CVSS 3.1
AVPACLPRNUINSUCLILAN
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianjetty9< jetty9 9.4.39-2 (bookworm)jetty9 9.4.39-2 (bookworm)
eclipsejetty<= 9.4.40
eclipsejetty10.0.0 – 10.0.2
eclipsejetty11.0.0 – 11.0.2
netappe-series_santricity_os_controller11.0 – 11.70.1
oracleautovue_for_agile_product_lifecycle_management
oraclecommunications_element_manager
oraclecommunications_services_gatekeeper
oraclecommunications_session_report_manager8.0.0.0 – 8.2.4.0
oraclecommunications_session_route_manager8.0.0 – 8.2.4.0
oraclerest_data_services< 21.321.3
oraclesiebel_core_automation<= 21.9
the_eclipse_foundationeclipse_jetty>= 10.0.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= 11.0.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= 9.0.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jettyunspecified – 9.4.40

CVSS provenance

nvdv3.13.5LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv3.5LOW