Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Physical
0

CVE-2021-34428

Disclosure Date: June 22, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
3.5 Low
Impact Score:
2.5
Exploitability Score:
0.9
Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector (AV):
Physical
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
Low
Integrity (I):
Low
Availability (A):
None

General Information

Vendors

  • debian,
  • eclipse,
  • netapp,
  • oracle

Products

  • active iq unified manager -,
  • autovue for agile product lifecycle management 21.0.2,
  • communications element manager 8.2.2,
  • communications services gatekeeper 7.0,
  • communications session report manager,
  • communications session route manager,
  • debian linux 10.0,
  • e-series santricity os controller,
  • e-series santricity web services -,
  • element plug-in for vcenter server -,
  • jetty,
  • rest data services,
  • santricity cloud connector -,
  • siebel core - automation,
  • snap creator framework -,
  • snapmanager -

References

Additional Info

Technical Analysis