In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.
We have discovered 2,567 live websites that are affected by CVE-2018-12538.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 2,567 live websites (100% of Jetty install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 526 websites | |
| 943 websites | |
| 339 websites | |
| 91 websites | |
| 77 websites | |
| 65 websites | |
| 52 websites | |
| 49 websites | |
| 42 websites | |
| 38 websites |
| .com | 541 websites |
| .net | 215 websites |
| .de | 149 websites |
| .org | 100 websites |
| .se | 44 websites |
| .edu | 36 websites |
| .com.au | 23 websites |
| .pl | 20 websites |
| .at | 17 websites |
| .fr | 17 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.rocks | **,*** | ||
| ******.***.***.br | **,*** | ||
| *********.se | **,*** | ||
| *******.org | **,*** | ||
| ***.***.at | **,*** | ||
| **********.**.com | **,*** | ||
| *****.****.edu | **,*** | ||
| ***.**********.edu | **,*** | ||
| ******.***.es | ***,*** | ||
| ******.com | ***,*** |
FAQ