GHSA-pwh8-58vv-vw48 · Severity: low · Ecosystem: maven — Jetty's OpenId Revoked authentication allows one request
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already authenticated user, then the current request will still treat the user as authenticated. The authentication is then cleared from the session and subsequent requests will not be treated as authenticated. So a request on a previously authenticated session could be allowed to bypass authentication after it had been rejected by the `LoginService`. This impacts usages of the jetty-openid which have configured a nested `LoginService` and where that `LoginService` will is capable of rejecting previously authenticated users. Versions 9.4.52, 10.0.16, and 11.0.16 have a patch for this issue.
Conclusion & alert: CVE-2023-41900 is rated Exploit Available (50/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.14%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-03 | 0.19% | 0.14% | -0.05% |
| 2 | 2026-05-02 | 0.13% | 0.19% | +0.06% |
| 3 | 2025-11-21 | — | 0.13% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 3.5 | 3.1 | LOW |
|
1.8 | 1.4 | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
GHSA-pwh8-58vv-vw48 · Severity: low · Ecosystem: maven — Jetty's OpenId Revoked authentication allows one request
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-41900 not yet assigned priority: Debian including 1 source packages (jetty9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2023-41900 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2023-41900 |
suse
|
low | CVE-2023-41900 severity low: SUSE including 58 source package names (jetty-annotations-9.4.53-1.1, jetty-annotations-9.4.53-150200.3.22.1, …), 234 product×package rows across 21 product lines (Image server-image, SUSE Enterprise Storage 7.1, … (21 product lines)): Fixed 234. | https://www.suse.com/security/cve/CVE-2023-41900/ |
ubuntu
|
medium | CVE-2023-41900 medium priority: Ubuntu including 1 source packages (jetty9), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needed 4, not-affected 4, ignored 3, released 1. | https://ubuntu.com/security/CVE-2023-41900 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| eclipse | jetty | >= 9.4.21, < 9.4.52 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 10.0.0, < 10.0.16 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| eclipse | jetty | >= 11.0.0, < 11.0.16 | cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| debian | debian_linux | 12.0 | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/eclipse/jetty.project/pull/9528 | Patch |
| https://github.com/eclipse/jetty.project/pull/9660 | Patch |
| https://github.com/eclipse/jetty.project/security/advisories/GHSA-pwh8-58vv-vw48 | Exploit Patch Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20231110-0004/ | Third Party Advisory |
| https://www.debian.org/security/2023/dsa-5507 | Third Party Advisory |