CVE-2024-22201
published 2024-02-26CVE-2024-22201: Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.43%
70.3th percentile
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jetty9 | < jetty9 9.4.50-4+deb12u3 (bookworm) | jetty9 9.4.50-4+deb12u3 (bookworm) |
| eclipse | jetty | >= 10.0.0 < 10.0.20 | 10.0.20 |
| eclipse | jetty | >= 11.0.0 < 11.0.20 | 11.0.20 |
| eclipse | jetty | >= 12.0.0 < 12.0.6 | 12.0.6 |
| eclipse | jetty | >= 9.3.0 < 9.4.54 | 9.4.54 |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jetty | jetty.project | — | — |
| jetty | jetty.project | — | — |
| jetty | jetty.project | — | — |
| jetty | jetty.project | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Servlet Container (Eclipse Jetty) — CVE-2024-22201
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2024-22201 [HIGH] Oracle Oracle Supply Chain Risk Matrix: Servlet Container (Eclipse Jetty) — CVE-2024-22201
Oracle Oracle Supply Chain Risk Matrix: Servlet Container (Eclipse Jetty) vulnerability
CVE: CVE-2024-22201
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Broadband Solution (Eclipse Jetty) — CVE-2024-22201
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-22201 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Broadband Solution (Eclipse Jetty) — CVE-2024-22201
Oracle Oracle Communications Applications Risk Matrix: Broadband Solution (Eclipse Jetty) vulnerability
CVE: CVE-2024-22201
CVSS: 7.5
Protocol: HTTP/2
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Install (Eclipse Jetty) — CVE-2024-22201
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-22201 [HIGH] Oracle Oracle Communications Risk Matrix: Install (Eclipse Jetty) — CVE-2024-22201
Oracle Oracle Communications Risk Matrix: Install (Eclipse Jetty) vulnerability
CVE: CVE-2024-22201
CVSS: 7.5
Protocol: HTTP/2
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Eclipse Jetty) — CVE-2024-22201
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2024-22201 [HIGH] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Eclipse Jetty) — CVE-2024-22201
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Eclipse Jetty) vulnerability
CVE: CVE-2024-22201
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Jenkins
Jenkins Security Advisory 2024-03-20
vendor_jenkins·2024-03-20·CVSS 7.5
CVE-2024-22201 [HIGH] Jenkins Security Advisory 2024-03-20
Title: Jenkins Security Advisory 2024-03-20
Jenkins Security Advisory 2024-03-20
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Jenkins (core)
Descriptions
HTTP/2 denial of service vulnerability in bundled Jetty
SECURITY-3379
/
CVE-2024-22201
Severity (CVSS):
High
Description:
Jenkins bundles Winstone-Je
Red Hat
jetty: stop accepting new connections from valid clients
vendor_redhat·2024-02-26·CVSS 7.5
CVE-2024-22201 [HIGH] CWE-400 jetty: stop accepting new connections from valid clients
jetty: stop accepting new connections from valid clients
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.
A flaw was found in Jetty, a Java based web server and servlet engine. If an HTTP/2 connection gets TCP congested, it remains open and idle, and connections may be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the
Debian
CVE-2024-22201: jetty9 - Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection th...
vendor_debian·2024·CVSS 7.5
CVE-2024-22201 [HIGH] CVE-2024-22201: jetty9 - Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection th...
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.
Scope: local
bookworm: resolved (fixed in 9.4.50-4+deb12u3)
bullseye: resolved (fixed in 9.4.50-4+deb11u2)
forky: resolved (fixed in 9.4.54-1)
sid: resolved (fixed in 9.4.54-1)
trixie: resolved (fixed in 9.4.54-1)
OSV
CVE-2024-22201: Jetty is a Java based web server and servlet engine
osv·2024-02-26·CVSS 7.5
CVE-2024-22201 [HIGH] CVE-2024-22201: Jetty is a Java based web server and servlet engine
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.
OSV
Connection leaking on idle timeout when TCP congested
osv·2024-02-26
CVE-2024-22201 [HIGH] Connection leaking on idle timeout when TCP congested
Connection leaking on idle timeout when TCP congested
### Impact
If an HTTP/2 connection gets TCP congested, when an idle timeout occurs the HTTP/2 session is marked as closed, and then a GOAWAY frame is queued to be written.
However it is not written because the connection is TCP congested.
When another idle timeout period elapses, it is then supposed to hard close the connection, but it delegates to the HTTP/2 session which reports that it has already been closed so it does not attempt to hard close the connection.
This leaves the connection in ESTABLISHED state (i.e. not closed), TCP congested, and idle.
An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from v
GHSA
Connection leaking on idle timeout when TCP congested
ghsa·2024-02-26
CVE-2024-22201 [HIGH] CWE-400 Connection leaking on idle timeout when TCP congested
Connection leaking on idle timeout when TCP congested
### Impact
If an HTTP/2 connection gets TCP congested, when an idle timeout occurs the HTTP/2 session is marked as closed, and then a GOAWAY frame is queued to be written.
However it is not written because the connection is TCP congested.
When another idle timeout period elapses, it is then supposed to hard close the connection, but it delegates to the HTTP/2 session which reports that it has already been closed so it does not attempt to hard close the connection.
This leaves the connection in ESTABLISHED state (i.e. not closed), TCP congested, and idle.
An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from v
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/03/20/2https://github.com/jetty/jetty.project/issues/11256https://github.com/jetty/jetty.project/security/advisories/GHSA-rggv-cv7r-mw98https://lists.debian.org/debian-lts-announce/2024/04/msg00002.htmlhttps://security.netapp.com/advisory/ntap-20240329-0001/http://www.openwall.com/lists/oss-security/2024/03/20/2https://github.com/jetty/jetty.project/issues/11256https://github.com/jetty/jetty.project/security/advisories/GHSA-rggv-cv7r-mw98https://lists.debian.org/debian-lts-announce/2024/04/msg00002.htmlhttps://security.netapp.com/advisory/ntap-20240329-0001/
2024-02-26
Published