cbcvebase.
CVE-2024-6762
published 2024-10-14

CVE-2024-6762: Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianjetty9< jetty9 9.4.57-0+deb12u1 (bookworm)jetty9 9.4.57-0+deb12u1 (bookworm)
eclipsejetty>= 10.0.0 < 10.0.1810.0.18
eclipsejetty>= 11.0.0 < 11.0.1811.0.18
eclipsejetty>= 12.0.0 < 12.0.412.0.4
eclipse_foundationjetty10.0.0 – 10.0.17
eclipse_foundationjetty11.0.0 – 11.0.17
eclipse_foundationjetty12.0.0 – 12.0.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM