Uploaded image for project: 'Debezium'
  1. Debezium
  2. DBZ-8321

CVE-2024-9823 org.eclipse.jetty/jetty-servlets: Jetty DOS vulnerability on DosFilter [rhint-debezium-2]

XMLWordPrintable

    • False
    • None
    • False
    • CVEORG
    • CVE-2024-9823
    • Moderate
    • 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    • CWE-400
    • org.eclipse.jetty/jetty-servlets
    • jetty; org.eclipse.jetty:jetty-servlets
    • False

      Security Tracking Issue

      Do not make this issue public.

      Flaw:


      Jetty DOS vulnerability on DosFilter
      https://bugzilla.redhat.com/show_bug.cgi?id=2318565

      There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.

      ~~~

              Unassigned Unassigned
              rh-ee-rgatica Robb Gatica
              Chess Hazlett, Chris Cranford, Jakub Čecháček, Jiri Pechanec, Jonathan Anstey
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: