For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-continuationUpgrade jetty-serverUpgrade jetty-servletUpgrade jetty-jaspiUpgrade jetty-util-ajaxUpgrade jetty-startUpgrade jetty-proxyUpgrade jetty-xmlUpgrade jetty-websocket-parentUpgrade jetty-jspUpgrade jetty-maven-pluginUpgrade jetty-webappUpgrade jetty-servletsUpgrade jetty-websocket-servletUpgrade jetty-jndiUpgrade jetty-websocket-apiUpgrade jetty-runnerUpgrade jetty-jspc-maven-pluginUpgrade jetty-jaasUpgrade jetty-websocket-serverUpgrade jetty-projectUpgrade jetty-ioUpgrade jetty-httpUpgrade jetty-rewriteUpgrade jetty-deployUpgrade jetty-securityUpgrade jetty-utilUpgrade jetty-websocket-commonUpgrade jetty-antUpgrade jetty-javadocUpgrade jetty-websocket-clientUpgrade jetty-plusUpgrade jetty-annotationsUpgrade jetty-monitorUpgrade jetty-clientUpgrade jetty-jmx | May 14, 2025 | Jun 22, 2021 |
| Debian | — | Upgrade jetty9 | Aug 6, 2021 | Jun 22, 2021 |
| Redhat Openshift | — | Upgrade jenkins | Oct 20, 2021 | Jun 22, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 22, 2021 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub