CVE-2021-34428 affects Eclipse Jetty versions <= 9.4.40, <= 10.0.2, and <= 11.0.2, as well as products like Debian, NetApp, and Oracle that utilize vulnerable Jetty versions. The vulnerability arises when an exception in SessionListener#sessionDestroyed() prevents session ID invalidation, potentially leaving sessions active on shared computers, leading to unauthorized access. With a CVSS score of 3.5 (LOW), it has a physical attack vector and low complexity, resulting in low confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.2CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
<= 11.0.2CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
<= 9.4.40CPE match | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 10.0.0, <= 10.0.2CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 11.0.0, <= 11.0.2CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.