CVE-2018-12538CWE-6
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is…
published June 22, 2018
What it is
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
The record
Technical detail
- CVSS
- Not scored
- CVSS v4.0
- Not supplied
- EPSS
- 0.02654 · 84.7th percentile
- Weakness
- CWE-6 · J2EE Misconfiguration: Insufficient Session-ID Length
- Published
- 2018-06-22T19:00Z
EPSS history
Timeline