UBUNTU-CVE-2021-34428
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-34428
Summary:
Details: For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
References: https://ubuntu.com/security/CVE-2021-34428, https://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6, https://github.com/eclipse/jetty.project/issues/6277, https://www.cve.org/CVERecord?id=CVE-2021-34428
Affected packages
Package
Name: jetty
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
