CVE-2021-34428
3.5
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 0.9 / Impact: 2.5
Source: NVD
Description
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
Affected (19)
Products: Eclipse: Jetty · Debian: Debian Linux · Netapp: Active Iq Unified Manager, E Series Santricity Os Controller, E Series Santricity Web Services, Element Plug In For Vcenter Server, Santricity Cloud Connector, Snap Creator Framework, Snapmanager · +1 more
Show all products
Eclipse: Jetty · Debian: Debian Linux · Netapp: Active Iq Unified Manager, E Series Santricity Os Controller, E Series Santricity Web Services, Element Plug In For Vcenter Server, Santricity Cloud Connector, Snap Creator Framework, Snapmanager · Oracle: Autovue For Agile Product Lifecycle Management, Communications Element Manager, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Rest Data Services, Siebel Core Automation
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| From 11.0 to 11.70.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 21.0.2 | |
| Version 8.2.2 | |
| Version 7.0 | |
| From 8.0.0.0 to 8.2.4.0 | |
| From 8.0.0 to 8.2.4.0 | |
| Before 21.3 | |
| Up to 21.9 |
References (24)
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Source: emo@eclipse.org
Not ApplicableThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.