Source: jetty9 Version: 9.4.39-1 Severity: important Tags: security upstream Forwarded: https://github.com/eclipse/jetty.project/issues/6277 X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Hi, The following vulnerability was published for jetty9. CVE-2021-34428[0]: | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, | if an exception is thrown from the SessionListener#sessionDestroyed() | method, then the session ID is not invalidated in the session ID | manager. On deployments with clustered sessions and multiple contexts | this can result in a session not being invalidated. This can result in | an application used on a shared computer being left logged in. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2021-34428 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34428 [1] https://github.com/eclipse/jetty.project/issues/6277 [2] https://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6 Please adjust the affected versions in the BTS as needed. Regards, Salvatore