For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-antUpgrade jetty-websocket-serverUpgrade jetty-jmxUpgrade jetty-projectUpgrade jetty-utilUpgrade jetty-rewriteUpgrade jetty-deployUpgrade jetty-clientUpgrade jetty-ioUpgrade jetty-jaasUpgrade jetty-plusUpgrade jetty-javadocUpgrade jetty-securityUpgrade jetty-jspc-maven-pluginUpgrade jetty-runnerUpgrade jetty-httpUpgrade jetty-monitorUpgrade jetty-websocket-clientUpgrade jetty-annotationsUpgrade jetty-websocket-commonUpgrade jetty-websocket-apiUpgrade jetty-servletsUpgrade jetty-startUpgrade jetty-proxyUpgrade jetty-serverUpgrade jetty-jndiUpgrade jetty-servletUpgrade jetty-maven-pluginUpgrade jetty-jaspiUpgrade jetty-xmlUpgrade jetty-webappUpgrade jetty-websocket-parentUpgrade jetty-jspUpgrade jetty-util-ajaxUpgrade jetty-continuationUpgrade jetty-websocket-servlet | May 14, 2025 | Jun 22, 2021 |
| Debian | — | Upgrade jetty9 | Aug 6, 2021 | Jun 22, 2021 |
| Redhat Openshift | — | Upgrade jenkins | Oct 20, 2021 | Jun 22, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 22, 2021 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub