CVE-2018-12538
Last modified
CVE-2018-12538 is a vulnerability of currently unknown severity. In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Jetty | >= 9.4.0, <= 9.4.8 |
| Netapp | E-Series Santricity Management Plug-Ins | All versions |
| Netapp | E-Series Santricity Os Controller | >= 11.0, <= 11.40 |
| Netapp | E-Series Santricity Web Services Proxy | All versions |
| Netapp | Element Software | All versions |
| Netapp | Hyper Converged Infrastructure | All versions |
| Netapp | Oncommand System Manager | >= 3.0.0, <= 3.1.3 |
| Netapp | Oncommand Unified Manager | All versions |
| Netapp | Santricity Cloud Connector | All versions |
| Netapp | Snap Creator Framework | All versions |
| Netapp | Snapcenter | All versions |
| Netapp | Snapmanager | All versions |
References
- http://www.securitytracker.com/id/1041194Third Party Advisory, VDB Entry
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20181014-0001/Third Party Advisory
- http://www.securitytracker.com/id/1041194Third Party Advisory, VDB Entry
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20181014-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12538?
How severe is CVE-2018-12538?
How do I fix CVE-2018-12538?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12531An issue was discovered in MetInfo 6.0.0. install\index.php …
- CVE-2018-12532JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated …
- CVE-2018-12533JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated r…
- CVE-2018-12534A SQL injection issue was discovered in the Quick Chat plugi…
- CVE-2018-12536In Eclipse Jetty Server, all 9.x versions, on webapps deploy…5.3
- CVE-2018-12537In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer respo…
- CVE-2018-12539In Eclipse OpenJ9 version 0.8, users other than the process …
- CVE-2018-1254RSA Authentication Manager Security Console, versions 8.3 P1…
- CVE-2018-12540In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHa…
- CVE-2018-12541In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSoc…6.5
- CVE-2018-12542In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the Static…
- CVE-2018-12543In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a m…
Are you affected by CVE-2018-12538?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
