QID 997477
Date Published: 2024-02-26
QID 997477: Java (Maven) Security Update for org.eclipse.jetty:jetty-server (GHSA-jg2x-r643-w2ch)
Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site request forgery attacks.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-jg2x-r643-w2ch for updates and patch information.
Vendor References
- GHSA-jg2x-r643-w2ch -
github.com/advisories/GHSA-jg2x-r643-w2ch
CVEs related to QID 997477
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jg2x-r643-w2ch | org.eclipse.jetty:jetty-server |
|