-
Vulnerability
-
Resolution: Not a Bug
-
Major
-
None
-
2.5.4.GA
-
False
-
None
-
False
-
-
-
CVEORG
-
CVE-2024-9823
-
Moderate
-
5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
-
CWE-400
-
org.eclipse.jetty/jetty-servlets
-
jetty; org.eclipse.jetty:jetty-servlets
-
False
Security Tracking Issue
Do not make this issue public.
Flaw:
Jetty DOS vulnerability on DosFilter
https://bugzilla.redhat.com/show_bug.cgi?id=2318565
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
~~~