In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.
A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-jaspiUpgrade jetty-serverUpgrade jetty-clientUpgrade jetty-maven-pluginUpgrade jetty-monitorUpgrade jetty-jspUpgrade jetty-continuationUpgrade jetty-ioUpgrade jetty-securityUpgrade jetty-antUpgrade jetty-plusUpgrade jetty-projectUpgrade jetty-util-ajaxUpgrade jetty-websocket-serverUpgrade jetty-startUpgrade jetty-jspc-maven-pluginUpgrade jetty-annotationsUpgrade jetty-httpUpgrade jetty-jmxUpgrade jetty-jndiUpgrade jetty-xmlUpgrade jetty-runnerUpgrade jetty-deployUpgrade jetty-websocket-servletUpgrade jetty-webappUpgrade jetty-utilUpgrade jetty-javadocUpgrade jetty-websocket-commonUpgrade jetty-websocket-apiUpgrade jetty-jaasUpgrade jetty-websocket-clientUpgrade jetty-websocket-parentUpgrade jetty-rewriteUpgrade jetty-servletsUpgrade jetty-servletUpgrade jetty-proxy | May 20, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub