CVE-2021-34428

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

Risk Information

Base Score
3.5
MODERATE
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.669

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-34428 are fixed in Eclipse-jetty-server 9.4.41Windows
Vulnerabilities CVE-2021-34428 are fixed in Eclipse-jetty-server 10.0.3Windows
Vulnerabilities CVE-2021-34428 are fixed in Eclipse-jetty-server 11.0.3Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Security Verify Directory Integrator 10.0.0Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.1.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
jetty9 security update(DSA-4949-1) jetty9_9.4.16-0+deb10u1_all.debLinux
jetty Security Update (ALAS-2025-2855) jetty-xml-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-websocket-servlet-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-websocket-server-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-websocket-parent-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-websocket-common-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-websocket-client-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-websocket-api-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-webapp-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-util-ajax-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-util-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-start-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-servlets-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-servlet-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-server-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-security-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-runner-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-rewrite-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-proxy-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-project-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-plus-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-monitor-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-maven-plugin-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-jspc-maven-plugin-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-jsp-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-jndi-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-jmx-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-javadoc-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-jaspi-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-jaas-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-io-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-http-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-deploy-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-continuation-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-client-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-ant-9.0.3-8.amzn2.0.5.noarch.rpmLinux
jetty Security Update (ALAS-2025-2855) jetty-annotations-9.0.3-8.amzn2.0.5.noarch.rpmLinux
Vulnerabilities CVE-2021-34428 are fixed in Eclipse-jetty-server for Linux 9.4.41Linux
Vulnerabilities CVE-2021-34428 are fixed in Eclipse-jetty-server for Linux 10.0.3Linux
Vulnerabilities CVE-2021-34428 are fixed in Eclipse-jetty-server for Linux 11.0.3Linux
Insufficient Session Expiration Vulnerability (CVE-2021-34428)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234