Improper Authorization in Jetty - CVE-2023-41900

 

Improper Authorization in Jetty - CVE-2023-41900

Published: September 14, 2023 / Updated: October 12, 2023


Vulnerability identifier: #VU80793
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41900
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to an error in the revocation process. If a Jetty OpenIdAuthenticator uses the optional nested LoginService, and that LoginService decides to revoke an already authenticated user, then the current request will still treat the user as authenticated.


Affected software

Jetty
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
IBM Operations Analytics Predictive Insights
IBM Sterling B2B Integrator
IBM Sterling Control Center
Rational Service Tester
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
IBM Process Mining
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling Connect:Direct for UNIX
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
UCD - IBM UrbanCode Deploy
Rational Functional Tester (RFT)
IBM Content Collector for SAP Applications
Cloud Pak for Network Automation
DataStage on Cloud Pak for Data
Rational Performance Tester
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
User Entity Behavior Analytics
IBM Sterling Connect:Direct for Microsoft Windows
IBM Secure External Authentication Server
Rational Synergy
Storage Protect Server
Rational Change
Sterling Connect:Direct Browser User Interface
Fuse
IBM MaaS360 VPN Module
Operational Decision Manager
IBM Cognos Analytics
jetty9 (Debian package)
jetty-xml
jetty-util
jetty-http
jetty-servlet
jetty-security
jetty-http-spi
jetty-io
jetty-util-ajax
jetty-cdi
jetty-servlets
jetty-rewrite
jetty-plus
jetty-minimal-javadoc
jetty-ant
jetty-openid
jetty-start
jetty-jmx
jetty-fcgi
jetty-webapp
jetty-proxy
jetty-continuation
jetty-jsp
jetty-deploy
jetty-client
jetty-jaas
jetty-server
jetty-jndi
jetty-quickstart
jetty-annotations
IBM Cognos Command Center

How to mitigate CVE-2023-41900

Install updates from vendor's website.

Jetty - addressed in versions 9.4.52.v20230823, 10.0.16, 11.0.16
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
Cloud Pak for Network Automation - update to 2.7.2
DataStage on Cloud Pak for Data - update to 5.0.0
Rational Change - update to 5.3.2.7
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Sterling Control Center - update to 6.2.1.0.15
Fuse - update to 7.12.1
Rational Service Tester - update to 11.0.0
Rational Performance Tester - update to 11.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
IBM Automation Decision Services - update to 23.0.1 IF005
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-39
IBM Process Mining - update to 1.14.2.0.1
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 VPN Module - update to 3.000.400
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
User Entity Behavior Analytics - update to 5.0.2
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.0.0.2.159, 6.1.0.4.99, 6.2.0.7.5, 6.3.0.2.5
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.0.0.4.83, 6.1.0.2.79, 6.2.0.6.7, 6.3.0.2.6
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.22, 6.2.0.20, 6.3.0.5
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.19, 7.1.2.15, 7.2.3.8, 7.3.2.3
Rational Synergy - update to 7.2.2.7
Storage Protect Server - update to 8.1.21
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 47, 8.11.0.1 Interim fix 25, 8.11.1 Interim fix 15, 8.12.0 Interim fix 6
jetty9 (Debian package) - addressed in versions 9.4.39-3+deb11u2, 9.4.50-4+deb12u1
jetty-xml - update to 9.4.53-150200.3.22.1
jetty-util - update to 9.4.53-150200.3.22.1
jetty-http - update to 9.4.53-150200.3.22.1
jetty-servlet - update to 9.4.53-150200.3.22.1
jetty-security - update to 9.4.53-150200.3.22.1
jetty-http-spi - update to 9.4.53-150200.3.22.1
jetty-io - update to 9.4.53-150200.3.22.1
jetty-util-ajax - update to 9.4.53-150200.3.22.1
jetty-cdi - update to 9.4.53-150200.3.22.1
jetty-servlets - update to 9.4.53-150200.3.22.1
jetty-rewrite - update to 9.4.53-150200.3.22.1
jetty-plus - update to 9.4.53-150200.3.22.1
jetty-minimal-javadoc - update to 9.4.53-150200.3.22.1
jetty-ant - update to 9.4.53-150200.3.22.1
jetty-openid - update to 9.4.53-150200.3.22.1
jetty-start - update to 9.4.53-150200.3.22.1
jetty-jmx - update to 9.4.53-150200.3.22.1
jetty-fcgi - update to 9.4.53-150200.3.22.1
jetty-webapp - update to 9.4.53-150200.3.22.1
jetty-proxy - update to 9.4.53-150200.3.22.1
jetty-continuation - update to 9.4.53-150200.3.22.1
jetty-jsp - update to 9.4.53-150200.3.22.1
jetty-deploy - update to 9.4.53-150200.3.22.1
jetty-client - update to 9.4.53-150200.3.22.1
jetty-jaas - update to 9.4.53-150200.3.22.1
jetty-server - update to 9.4.53-150200.3.22.1
jetty-jndi - update to 9.4.53-150200.3.22.1
jetty-quickstart - update to 9.4.53-150200.3.22.1
jetty-annotations - update to 9.4.53-150200.3.22.1
IBM Cognos Command Center - update to 10.2.5
Rational Functional Tester (RFT) - update to 11.0.0
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Content Collector for SAP Applications - update to 21.0.3 IF031

External References

Related Security Bulletins