CVE-2018-12538
Last modified
CVE-2018-12538 is a vulnerability of currently unknown severity. In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Jetty | >= 9.4.0, <= 9.4.8 |
| Netapp | E-Series Santricity Management Plug-Ins | All versions |
| Netapp | E-Series Santricity Os Controller | >= 11.0, <= 11.40 |
| Netapp | E-Series Santricity Web Services Proxy | All versions |
| Netapp | Element Software | All versions |
| Netapp | Hyper Converged Infrastructure | All versions |
| Netapp | Oncommand System Manager | >= 3.0.0, <= 3.1.3 |
| Netapp | Oncommand Unified Manager | All versions |
| Netapp | Santricity Cloud Connector | All versions |
| Netapp | Snap Creator Framework | All versions |
| Netapp | Snapcenter | All versions |
| Netapp | Snapmanager | All versions |
References
- http://www.securitytracker.com/id/1041194Third Party Advisory, VDB Entry
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20181014-0001/Third Party Advisory
- http://www.securitytracker.com/id/1041194Third Party Advisory, VDB Entry
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20181014-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12538?
How severe is CVE-2018-12538?
How do I fix CVE-2018-12538?
Are you affected by CVE-2018-12538?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
