For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
CVSS Details
- CVSS 3.1 Base Score: 2.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-websocket-apiUpgrade jetty-continuationUpgrade jetty-websocket-servletUpgrade jetty-servletUpgrade jetty-proxyUpgrade jetty-servletsUpgrade jetty-webappUpgrade jetty-jaspiUpgrade jetty-maven-pluginUpgrade jetty-jspUpgrade jetty-startUpgrade jetty-util-ajaxUpgrade jetty-websocket-parentUpgrade jetty-xmlUpgrade jetty-serverUpgrade jetty-jndiUpgrade jetty-plusUpgrade jetty-utilUpgrade jetty-monitorUpgrade jetty-rewriteUpgrade jetty-deployUpgrade jetty-websocket-clientUpgrade jetty-javadocUpgrade jetty-securityUpgrade jetty-runnerUpgrade jetty-httpUpgrade jetty-projectUpgrade jetty-jspc-maven-pluginUpgrade jetty-websocket-serverUpgrade jetty-antUpgrade jetty-websocket-commonUpgrade jetty-clientUpgrade jetty-jaasUpgrade jetty-ioUpgrade jetty-jmxUpgrade jetty-annotations | May 14, 2025 | Jun 22, 2021 |
| Debian | — | Upgrade jetty9 | Aug 6, 2021 | Jun 22, 2021 |
| Redhat Openshift | — | Upgrade jenkins | Oct 20, 2021 | Jun 22, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 22, 2021 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Jun 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub