{"id":"GHSA-mwcx-532g-8pq3","summary":"Access and integrity issue within Eclipse Jetty","details":"In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.","aliases":["CVE-2018-12538"],"modified":"2024-02-17T05:43:52.147542Z","published":"2018-10-16T17:44:11Z","database_specific":{"cwe_ids":["CWE-384","CWE-6"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:47:31Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12538"},{"type":"WEB","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=536018"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mwcx-532g-8pq3"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20181014-0001"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"WEB","url":"http://www.securitytracker.com/id/1041194"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.4.0"},{"fixed":"9.4.11.v20180605"}]}],"versions":["9.4.0.v20161208","9.4.0.v20180619","9.4.1.v20170120","9.4.1.v20180619","9.4.10.RC0","9.4.10.RC1","9.4.10.v20180503","9.4.2.v20170220","9.4.2.v20180619","9.4.3.v20170317","9.4.3.v20180619","9.4.4.v20170414","9.4.4.v20180619","9.4.5.v20170502","9.4.5.v20180619","9.4.6.v20170531","9.4.6.v20180619","9.4.7.RC0","9.4.7.v20170914","9.4.7.v20180619","9.4.8.v20171121","9.4.8.v20180619","9.4.9.v20180320"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-mwcx-532g-8pq3/GHSA-mwcx-532g-8pq3.json","last_known_affected_version_range":"\u003c= 9.4.10.v20180503"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}