CVE-2018-12538CWE-6

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is…

published June 22, 2018

CVSS
EPSS
3%
Percentile
84.7
In the wild
Unconfirmed
What it is

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.02654 · 84.7th percentile
Weakness
CWE-6 · J2EE Misconfiguration: Insufficient Session-ID Length
Published
2018-06-22T19:00Z
EPSS history
Timeline
  • 22 JUN 19:00Z
    In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is…
    cvelistv5