highCVSS 7.4Vulnerability

GHSA-gc59-r5jq-98qw

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-r7p8-xq5m-436c. This link is maintained to preserve external references. ## Original Description In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.

Properties

ghsa_id
GHSA-gc59-r5jq-98qw
summary
Duplicate Advisory: Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
severity
high
cvss_score
7.4
cve_id
GHSA-gc59-r5jq-98qw
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-04-08T15:31:44Z
source_url
https://github.com/advisories/GHSA-gc59-r5jq-98qw
ghsa_updated
2026-04-14T00:06:20Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]maven/org.eclipse.jetty.ee10:jetty-ee10

AFFECTS (1)

[Software]maven/org.eclipse.jetty.ee10:jetty-ee10

HAS_WEAKNESS (1)

[Weakness]Sensitive Information in Resource Not Removed Before Reuse

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-gc59-r5jq-98qw (CVSS 7.4) — Ninja Signal Threat Intelligence | Ninja Signal