QID 997477

Date Published: 2024-02-26

QID 997477: Java (Maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-jg2x-r643-w2ch)

Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Github security advisory GHSA-jg2x-r643-w2ch for updates and patch information.
    Vendor References

    CVEs related to QID 997477

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jg2x-r643-w2ch org.eclipse.jetty:jetty-server URL Logo github.com/advisories/GHSA-jg2x-r643-w2ch