Session fixation attack in Jetty - CVE-2018-12538
Published: June 29, 2018 / Updated: July 2, 2018
Vulnerability details
The vulnerability allows a remote attacker to a session fixation attack on a target system.
The vulnerability exists due to improper security restrictions when the FileSessionDataStore class is used for persistent storage of HTTP session details. A remote attacker can submit a partial session ID, delete other unmatched HTTP sessions from filesystem storage for the FileSessionDataStore class and hijack existing HTTP sessions or cause the service to crash.
Affected software
Fedora
Operational Decision Manager
IBM Cognos Analytics
jetty
How to mitigate CVE-2018-12538
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty - addressed in versions 9.4.11-2.v20180605.fc27, 9.4.11-2.v20180605.fc28
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4