PT-2023-5724 · Eclipse+3 · Jetty+3

Andrewmcguinness

·

Published

2023-03-23

·

Updated

2026-05-18

·

CVE-2023-41900

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jetty versions 9.4.21 through 9.4.51 Jetty version 10.0.15 Jetty version 11.0.15
Description The issue is related to weak authentication in Jetty when using the OpenIdAuthenticator with a nested LoginService. If the LoginService revokes an already authenticated user, the current request will still treat the user as authenticated. This allows a request on a previously authenticated session to bypass authentication after it has been rejected by the LoginService. This impacts usages of the jetty-openid that have configured a nested LoginService capable of rejecting previously authenticated users.
Recommendations For Jetty versions 9.4.21 through 9.4.51, upgrade to version 9.4.52 or later. For Jetty version 10.0.15, upgrade to version 10.0.16 or later. For Jetty version 11.0.15, upgrade to version 11.0.16 or later. As a temporary workaround, consider disabling the OpenIdAuthenticator until a patch is available. Restrict access to the vulnerable LoginService to minimize the risk of exploitation. Avoid using the LoginService in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-16002
ALT-PU-2024-16022
ALT-PU-2024-16072
BDU:2023-06394
CLEANSTART-2026-SQ91016
CLEANSTART-2026-WK99982
CVE-2023-41900
DSA-5507-1
GHSA-PWH8-58VV-VW48
OPENSUSE-SU-2023_4210-1
OPENSUSE-SU-2024:13329-1
SUSE-SU-2023:4210-1

Affected Products

Alt Linux
Jetty
Red Os
Suse