Lucene search

K
githubGitHub Advisory DatabaseGHSA-FVH3-4V5R-CVVC
HistoryMay 01, 2022 - 6:35 p.m.

Improper Authentication in Mortbay Jetty

2022-05-0118:35:01
CWE-287
GitHub Advisory Database
github.com
14
mortbay jetty
improper authentication
browser sessions

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.03

Percentile

91.1%

Mortbay Jetty before 6.1.6rc1 does not properly handle “certain quote sequences” in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

Affected configurations

Vulners
Node
org.mortbay.jettyjettyRange<6.1.6
VendorProductVersionCPE
org.mortbay.jettyjetty*cpe:2.3:a:org.mortbay.jetty:jetty:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.03

Percentile

91.1%