CVE-2018-12538: Eclipse Jetty
High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
Affected products
- Eclipse Jetty: from 9.4.0, up to and including 9.4.8
- Netapp E-Series Santricity Management Plug-Ins: affected versions not specified
- Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.40
- Netapp E-Series Santricity Web Services Proxy: affected versions not specified
- Netapp Element Software: affected versions not specified
- Netapp Hyper Converged Infrastructure: affected versions not specified
- Netapp Oncommand System Manager: from 3.0.0, up to and including 3.1.3
- Netapp Oncommand Unified Manager: affected versions not specified
- Netapp Santricity Cloud Connector: affected versions not specified
- Netapp Snap Creator Framework: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Netapp Snapmanager: affected versions not specified
Published 2018-06-22. Last modified 2026-06-17.