漏洞信息详情
Eclipse Jetty 代码问题漏洞
漏洞简介
Eclipse Jetty是Eclipse基金会的一个开源的、基于Java的Web服务器和Java Servlet容器。
Eclipse Jetty versions<= 9.4.40存在安全漏洞,该漏洞源于SessionListener抛出异常。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://lists.apache.org/thread.html/ref1c161a1621504e673f9197b49e6efe5a33ce3f0e6d8f1f804fc695@%3Cjira.kafka.apache.org%3E
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/r67c4f90658fde875521c949448c54c98517beecdc7f618f902c620ec@%3Cissues.zookeeper.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rddbb4f8d5db23265bb63d14ef4b3723b438abc1589f877db11d35450@%3Cissues.zookeeper.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rf36f1114e84a3379b20587063686148e2d5a39abc0b8a66ff2a9087a@%3Cissues.zookeeper.apache.org%3E
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20210813-0003/
来源:MLIST
链接:https://lists.apache.org/thread.html/ref1c161a1621504e673f9197b49e6efe5a33ce3f0e6d8f1f804fc695@%3Cjira.kafka.apache.org%3E
来源:MISC
链接:https://lists.apache.org/thread.html/r8a1a332899a1f92c8118b0895b144b27a78e3f25b9d58a34dd5eb084@%3Cnotifications.zookeeper.apache.org%3E
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:CONFIRM
链接:https://github.com/eclipse/jetty.project/security/advisories/GHSA-m6cp-vxjx-65j6
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4949
来源:MISC
链接:https://lists.apache.org/thread.html/rbefa055282d52d6b58d29a79fbb0be65ab0a38d25f00bd29eaf5e6fd@%3Cnotifications.zookeeper.apache.org%3E
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021080803
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021081922
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Eclipse-Jetty-privilege-escalation-via-SessionListener-sessionDestroyed-35752
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2636
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164346/Red-Hat-Security-Advisory-2021-3700-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021093016
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164542/Red-Hat-Security-Advisory-2021-3758-01.html
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-34428
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-34428
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3984
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2896
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3466
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3256
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021102117
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163922/Red-Hat-Security-Advisory-2021-3225-01.html
受影响实体
暂无
补丁
- Eclipse Jetty 代码问题漏洞的修复措施<!--2021-6-22-->
还没有评论,来说两句吧...