ZeroHour

CVE-2018-12538

CVSS 3.0
8.8 high
EPSS
3%p85
Published
()
Modified
Description

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

Vendors
eclipsenetapp
Products
jetty, e-series santricity management plug-ins, e-series santricity os controller, e-series santricity web services proxy, element software, hyper converged infrastructure, oncommand system manager, oncommand unified manager, santricity cloud connector, snap creator framework, snapcenter, snapmanager
Weakness
CWE-6, CWE-384
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.