QID 995296

Date Published: 2023-09-18

QID 995296: Java (Maven) Security Update for org.eclipse.jetty:jetty-openid (GHSA-pwh8-58vv-vw48)

If a Jetty OpenIdAuthenticator uses the optional nested LoginService, and that LoginService decides to revoke an already authenticated user, then the current request will still treat the user as authenticated. The authentication is then cleared from the session and subsequent requests will not be treated as authenticated.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-pwh8-58vv-vw48 for updates and patch information.
    Vendor References

    CVEs related to QID 995296

    Software Advisories
    Advisory ID Software Component Link
    GHSA-pwh8-58vv-vw48 org.eclipse.jetty:jetty-openid URL Logo github.com/advisories/GHSA-pwh8-58vv-vw48