Oval Definition:oval:com.ubuntu.xenial:def:201812538000
Revision Date:2018-06-22Version:1
Title:CVE-2018-12538 on Ubuntu 16.04 LTS (xenial) - medium.
Description:In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-12538
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'jetty' package in xenial is not affected (note: 'code not present').
  • OR NOT While related to the CVE in some way, the 'jetty9' package in xenial is not affected (note: 'code not present').
  • BACK