CVE-2018-12538
Summary
| CVE | CVE-2018-12538 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-22 19:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Jetty Multiple Flaws Let Remote Users Conduct HTTP Request Smuggling and Session Hijacking Attacks and Determine the Installation Path - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - October 2020 |
MISC |
www.oracle.com |
|
| 536018 – (CVE-2018-12538) Jetty: CVE Request: FileBasedSessionStore Session Stealing |
CONFIRM |
bugs.eclipse.org |
Issue Tracking, Vendor Advisory |
| September 2018 Eclipse Jetty Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Oracle Critical Patch Update - October 2019 |
MISC |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982312 Java (maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-mwcx-532g-8pq3)