CVE-2024-6762
published 2024-10-14CVE-2024-6762: Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.95%
57.3th percentile
Jetty PushSessionCacheFilter can be exploited by unauthenticated users
to launch remote DoS attacks by exhausting the server’s memory.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty9 | < jetty9 9.4.57-0+deb12u1 (bookworm) | jetty9 9.4.57-0+deb12u1 (bookworm) |
| eclipse | jetty | >= 10.0.0 < 10.0.18 | 10.0.18 |
| eclipse | jetty | >= 11.0.0 < 11.0.18 | 11.0.18 |
| eclipse | jetty | >= 12.0.0 < 12.0.4 | 12.0.4 |
| eclipse_foundation | jetty | 10.0.0 – 10.0.17 | — |
| eclipse_foundation | jetty | 11.0.0 – 11.0.17 | — |
| eclipse_foundation | jetty | 12.0.0 – 12.0.3 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.eclipse.jetty:jetty-servlets: jetty: Jetty PushSessionCacheFilter can cause remote DoS attacks
vendor_redhat·2024-10-14·CVSS 3.1
CVE-2024-6762 [LOW] CWE-400 org.eclipse.jetty:jetty-servlets: jetty: Jetty PushSessionCacheFilter can cause remote DoS attacks
org.eclipse.jetty:jetty-servlets: jetty: Jetty PushSessionCacheFilter can cause remote DoS attacks
Jetty PushSessionCacheFilter can be exploited by unauthenticated users
to launch remote DoS attacks by exhausting the server’s memory.
A flaw was found in Jetty. In certain circumstances, this flaw allows unauthenticated users to launch remote denial of service (DoS) attacks by exhausting the server’s memory in the Jetty PushSessionCacheFilter.
Package: org.eclipse.jetty/jetty-servlets (A-MQ Clients 2) - Not affected
Package: org.eclipse.jetty/jetty-servlets (OpenShift Serverless) - Not affected
Package: org.eclipse.jetty/jetty-servlets (Red Hat build of Apache Camel for Spring Boot 3) - Not affected
Package: org.eclipse.jetty/jetty-servlets (Red Hat build of Apache Camel for Spring Boo
Debian
CVE-2024-6762: jetty9 - Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launc...
vendor_debian·2024·CVSS 3.1
CVE-2024-6762 [LOW] CVE-2024-6762: jetty9 - Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launc...
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Scope: local
bookworm: resolved (fixed in 9.4.57-0+deb12u1)
bullseye: resolved (fixed in 9.4.57-0+deb11u1)
forky: resolved (fixed in 9.4.54-1)
sid: resolved (fixed in 9.4.54-1)
trixie: resolved (fixed in 9.4.54-1)
OSV
CVE-2024-6762: Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory
osv·2024-10-14·CVSS 6.5
CVE-2024-6762 [MEDIUM] CVE-2024-6762: Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
OSV
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
osv·2024-10-14
CVE-2024-6762 [LOW] Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
### Impact
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
### Patches
* https://github.com/jetty/jetty.project/pull/9715
* https://github.com/jetty/jetty.project/pull/9716
### Workarounds
The session usage is intrinsic to the design of the PushCacheFilter. The issue can be avoided by:
+ not using the PushCacheFilter. Push has been deprecated by the various IETF specs and early hints responses should be used instead.
+ reducing the reducing the idle timeout on unauthenticated sessions will reduce the time such session stay in memory.
+ configuring a session cache to use [session passivation](https://jetty.org/docs/jetty/12/programming
GHSA
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
ghsa·2024-10-14
CVE-2024-6762 [LOW] CWE-400 Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
### Impact
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
### Patches
* https://github.com/jetty/jetty.project/pull/9715
* https://github.com/jetty/jetty.project/pull/9716
### Workarounds
The session usage is intrinsic to the design of the PushCacheFilter. The issue can be avoided by:
+ not using the PushCacheFilter. Push has been deprecated by the various IETF specs and early hints responses should be used instead.
+ reducing the reducing the idle timeout on unauthenticated sessions will reduce the time such session stay in memory.
+ configuring a session cache to use [session passivation](https://jetty.org/docs/jetty/12/programming
No detection rules found.
No public exploits indexed.
https://github.com/jetty/jetty.project/pull/10755https://github.com/jetty/jetty.project/pull/10756https://github.com/jetty/jetty.project/pull/9715https://github.com/jetty/jetty.project/pull/9716https://github.com/jetty/jetty.project/security/advisories/GHSA-r7m4-f9h5-gr79https://gitlab.eclipse.org/security/cve-assignement/-/issues/24https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html
2024-10-14
Published