CVE-2021-34428

LOW

Eclipse Jetty <= 9.4.40 - Insufficient Session Expiration via SessionListener Exception

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-34428. PoCs published by Trinadh465.

AI-analyzed exploit summary This repository appears to be a fork of the Eclipse Jetty project with no specific exploit code or technical analysis for CVE-2021-34428. It contains standard project files, issue templates, and documentation but lacks any functional PoC or vulnerability details.

Description

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

Exploits (1)

nomisec STUB
by Trinadh465 · poc
https://github.com/Trinadh465/jetty_9.4.31_CVE-2021-34428

This repository appears to be a fork of the Eclipse Jetty project with no specific exploit code or technical analysis for CVE-2021-34428. It contains standard project files, issue templates, and documentation but lacks any functional PoC or vulnerability details.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Eclipse Jetty 9.4.31
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4949
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210813-0003/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Not Applicable, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 2.9
EPSS 0.0029
EPSS Percentile 53.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-613
Status published
Products (17)
debian/debian_linux 10.0
eclipse/jetty < 9.4.40
netapp/active_iq_unified_manager (2 CPE variants)
netapp/e-series_santricity_os_controller 11.0 - 11.70.1
netapp/e-series_santricity_web_services
netapp/element_plug-in_for_vcenter_server
netapp/santricity_cloud_connector
netapp/snap_creator_framework
netapp/snapmanager
oracle/autovue_for_agile_product_lifecycle_management 21.0.2
... and 7 more
Published Jun 22, 2021
Tracked Since Feb 18, 2026