LOW · 2.9

CVE-2021-34428

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manag...

Vulnerability Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVSS Score

2.9

LOW

CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EclipseJetty<= 9.4.40
DebianDebian Linux10.0
NetappActive Iq Unified Manager-
NetappE-Series Santricity Os Controller>= 11.0, <= 11.70.1
NetappE-Series Santricity Web Services-
NetappElement Plug-In For Vcenter Server-
NetappSantricity Cloud Connector-
NetappSnap Creator Framework-
NetappSnapmanager-
OracleAutovue For Agile Product Lifecycle Management21.0.2
OracleCommunications Element Manager8.2.2
OracleCommunications Services Gatekeeper7.0
OracleCommunications Session Report Manager>= 8.0.0.0, <= 8.2.4.0
OracleCommunications Session Route Manager>= 8.0.0, <= 8.2.4.0
OracleRest Data Services< 21.3
OracleSiebel Core - Automation<= 21.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-34428?

CVE-2021-34428 is a vulnerability with a CVSS score of 2.9 (LOW). For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manag...

How severe is CVE-2021-34428?

CVE-2021-34428 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-34428?

Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Jetty, Debian Debian Linux, Netapp Active Iq Unified Manager, Netapp E-Series Santricity Os Controller, Netapp E-Series Santricity Web Services.