Oval Definition:oval:com.ubuntu.artful:def:201812538000
Revision Date:2018-06-22Version:1
Title:CVE-2018-12538 on Ubuntu 17.10 (artful) - medium.
Description:In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-12538
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND The vulnerability of the 'jetty9' package in artful is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK