PT-2018-3158 · Eclipse+1 · Eclipse Jetty+1

Published

2018-05-30

·

Updated

2020-10-20

·

CVE-2018-12538

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 9.4.0 through 9.4.8
Description The issue is related to the use of the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details. A malicious user can access or hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore. This is due to an error in the J2EE configuration. Exploitation of the issue may allow a remote attacker to gain unauthorized access to protected information by managing sessions using the HttpSessions component from the FileSystem storage.
Recommendations For Eclipse Jetty versions 9.4.0 through 9.4.8, consider disabling the use of the FileSessionDataStore for persistent storage of HttpSession details until a patch is available. Restrict access to the FileSystem's storage for the FileSessionDataStore to minimize the risk of exploitation. Avoid using the HttpSessions component from the FileSystem storage in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1819
BDU:2019-04280
CVE-2018-12538
GHSA-MWCX-532G-8PQ3

Affected Products

Alt Linux
Eclipse Jetty