Eclipse Jetty is vulnerable to a ThreadLocal variable management flaw in its JASPIAuthenticator class. When certain conditions trigger an early return from authentication checks, ThreadLocal variables set during the initial authentication process are not properly cleared. Subsequent requests on the same thread inherit these uncleared ThreadLocal values, enabling attackers to bypass access controls and escalate privileges. The vulnerability presents a HIGH severity risk with a CVSS score of 7.4. It requires network access with high complexity but no user interaction or privileges, making it moderately difficult to exploit. The impact is significant, potentially compromising both the confidentiality and integrity of affected systems. There is no indication of active exploitation in the wild. The EPSS score of 0.0002 reflects minimal current exploitation probability, and the vulnerability is not listed in the Known Exploited Vulnerabilities catalog. Community attention appears limited, as evidenced by its inactive status on the Hot List, suggesting this issue has received relatively restrained attention from the security community despite its HIGH severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4.0, <= 9.4.58CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 10.0.0, <= 10.0.26CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 11.0.0, <= 11.0.26CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.0.34CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* | ||
>= 12.1.0, < 12.1.8CPE matchmatch criteria | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.