Session fixation attack in Jetty - CVE-2018-12538

 

Session fixation attack in Jetty - CVE-2018-12538

Published: June 29, 2018 / Updated: July 2, 2018


Vulnerability identifier: #VU13531
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12538
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to a session fixation attack on a target system.

The vulnerability exists due to improper security restrictions when the FileSessionDataStore class is used for persistent storage of HTTP session details. A remote attacker can submit a partial session ID, delete other unmatched HTTP sessions from filesystem storage for the FileSessionDataStore class and hijack existing HTTP sessions or cause the service to crash.


Affected software

Jetty
Fedora
Operational Decision Manager
IBM Cognos Analytics
jetty

How to mitigate CVE-2018-12538

Update to version 9.4.9.v20180320 or later.

Jetty - update to 9.4.9.v20180320
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty - addressed in versions 9.4.11-2.v20180605.fc27, 9.4.11-2.v20180605.fc28
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4

External References

Related Security Bulletins