CVE-2024-8184
published 2024-10-14CVE-2024-8184: There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.04%
60.1th percentile
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty9 | < jetty9 9.4.57-0+deb12u1 (bookworm) | jetty9 9.4.57-0+deb12u1 (bookworm) |
| eclipse | jetty | >= 10.0.0 < 10.0.24 | 10.0.24 |
| eclipse | jetty | >= 11.0.0 < 11.0.24 | 11.0.24 |
| eclipse | jetty | >= 12.0.0 < 12.0.9 | 12.0.9 |
| eclipse | jetty | >= 9.3.12 < 9.4.56 | 9.4.56 |
| eclipse_foundation | jetty | 10.0.0 – 10.0.23 | — |
| eclipse_foundation | jetty | 11.0.0 – 11.0.23 | — |
| eclipse_foundation | jetty | 12.0.0 – 12.0.8 | — |
| eclipse_foundation | jetty | 9.3.12 – 9.4.55 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
ghsa·2024-10-14
CVE-2024-8184 [MEDIUM] CWE-400 Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
### Impact
Remote DOS attack can cause out of memory
### Description
There exists a security vulnerability in Jetty's `ThreadLimitHandler.getRemote()` which
can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By
repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the
server's memory.
### Affected Versions
* Jetty 12.0.0-12.0.8 (Supported)
* Jetty 11.0.0-11.0.23 (EOL)
* Jetty 10.0.0-10.0.23 (EOL)
* Jetty 9.3.12-9.4.55 (EOL)
### Patched Versions
* Jetty 12.0.9
* Jetty 11.0.24
* Jetty 10.0.24
* Jetty 9.4.56
### Workarounds
Do not use `ThreadLimitHandler`.
Consider use of `QoSHandler` instead to artificially limit resource utilization.
OSV
CVE-2024-8184: There exists a security vulnerability in Jetty's ThreadLimitHandler
osv·2024-10-14·CVSS 6.5
CVE-2024-8184 [MEDIUM] CVE-2024-8184: There exists a security vulnerability in Jetty's ThreadLimitHandler
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.
OSV
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
osv·2024-10-14
CVE-2024-8184 [MEDIUM] Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
### Impact
Remote DOS attack can cause out of memory
### Description
There exists a security vulnerability in Jetty's `ThreadLimitHandler.getRemote()` which
can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By
repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the
server's memory.
### Affected Versions
* Jetty 12.0.0-12.0.8 (Supported)
* Jetty 11.0.0-11.0.23 (EOL)
* Jetty 10.0.0-10.0.23 (EOL)
* Jetty 9.3.12-9.4.55 (EOL)
### Patched Versions
* Jetty 12.0.9
* Jetty 11.0.24
* Jetty 10.0.24
* Jetty 9.4.56
### Workarounds
Do not use `ThreadLimitHandler`.
Consider use of `QoSHandler` instead to artificially limit resource utilization.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security (Eclipse Jetty) — CVE-2024-8184
vendor_oracle·2025-07-15·CVSS 5.9
CVE-2024-8184 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Security (Eclipse Jetty) — CVE-2024-8184
Oracle Oracle Fusion Middleware Risk Matrix: Security (Eclipse Jetty) vulnerability
CVE: CVE-2024-8184
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Red Hat
org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
vendor_redhat·2024-10-14·CVSS 5.9
CVE-2024-8184 [MEDIUM] CWE-400 org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.
A flaw was found in Jetty's ThreadLimitHandler.getRemote(). This flaw allows unauthorized users to cause remote denial of service (DoS) attacks. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.
Statement: This vulnerability is rated as moderate rather than important because it requires specific conditions to be met, including continuo
Debian
CVE-2024-8184: jetty9 - There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() ...
vendor_debian·2024·CVSS 5.9
CVE-2024-8184 [MEDIUM] CVE-2024-8184: jetty9 - There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() ...
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.
Scope: local
bookworm: resolved (fixed in 9.4.57-0+deb12u1)
bullseye: resolved (fixed in 9.4.57-0+deb11u1)
forky: resolved (fixed in 9.4.56-1)
sid: resolved (fixed in 9.4.56-1)
trixie: resolved (fixed in 9.4.56-1)
No detection rules found.
No public exploits indexed.
2024-10-14
Published