For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-ioUpgrade jetty-websocket-serverUpgrade jetty-jmxUpgrade jetty-clientUpgrade jetty-projectUpgrade jetty-utilUpgrade jetty-websocket-commonUpgrade jetty-jspc-maven-pluginUpgrade jetty-runnerUpgrade jetty-websocket-clientUpgrade jetty-monitorUpgrade jetty-plusUpgrade jetty-javadocUpgrade jetty-httpUpgrade jetty-securityUpgrade jetty-annotationsUpgrade jetty-antUpgrade jetty-jaasUpgrade jetty-rewriteUpgrade jetty-deployUpgrade jetty-continuationUpgrade jetty-websocket-parentUpgrade jetty-serverUpgrade jetty-websocket-apiUpgrade jetty-webappUpgrade jetty-servletUpgrade jetty-servletsUpgrade jetty-maven-pluginUpgrade jetty-jndiUpgrade jetty-startUpgrade jetty-websocket-servletUpgrade jetty-jspUpgrade jetty-proxyUpgrade jetty-jaspiUpgrade jetty-xmlUpgrade jetty-util-ajax | May 14, 2025 | Jun 22, 2021 |
| Debian | — | Upgrade jetty9 | Aug 6, 2021 | Jun 22, 2021 |
| Redhat Openshift | — | Upgrade jenkins | Oct 20, 2021 | Jun 22, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 22, 2021 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub