CVE-2024-9823
published 2024-10-14CVE-2024-9823: There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.95%
57.2th percentile
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jetty9 | < jetty9 9.4.57-0+deb12u1 (bookworm) | jetty9 9.4.57-0+deb12u1 (bookworm) |
| eclipse | jetty | >= 10.0.0 < 10.0.18 | 10.0.18 |
| eclipse | jetty | >= 11.0.0 < 11.0.18 | 11.0.18 |
| eclipse | jetty | >= 12.0.0 < 12.0.3 | 12.0.3 |
| eclipse | jetty | >= 9.0.0 < 9.4.54 | 9.4.54 |
| eclipse_foundation | jetty | >= 10.0.0 < 10.0.18 | 10.0.18 |
| eclipse_foundation | jetty | >= 11.0.0 < 11.0.18 | 11.0.18 |
| eclipse_foundation | jetty | >= 9.0.0 < 9.4.54 | 9.4.54 |
| eclipse_jetty | jetty | >= 12.0.0 < 12.0.3 | 12.0.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
vendor_redhat·2024-10-14·CVSS 5.3
CVE-2024-9823 [MEDIUM] CWE-400 org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
org.eclipse.jetty:jetty-servlets: jetty: Jetty DOS vulnerability on DosFilter
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
A flaw was found in Jetty. The DosFilter can be exploited remotely by unauthorized users to trigger an out-of-memory condition by repeatedly sending specially crafted requests. This issue may cause a crash, leading to a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and de
Debian
CVE-2024-9823: jetty9 - There exists a security vulnerability in Jetty's DosFilter which can be exploite...
vendor_debian·2024·CVSS 5.3
CVE-2024-9823 [MEDIUM] CVE-2024-9823: jetty9 - There exists a security vulnerability in Jetty's DosFilter which can be exploite...
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
Scope: local
bookworm: resolved (fixed in 9.4.57-0+deb12u1)
bullseye: resolved (fixed in 9.4.57-0+deb11u1)
forky: resolved (fixed in 9.4.54-1)
sid: resolved (fixed in 9.4.54-1)
trixie: resolved (fixed in 9.4.54-1)
OSV
Eclipse Jetty has a denial of service vulnerability on DosFilter
osv·2024-10-14
CVE-2024-9823 [MEDIUM] Eclipse Jetty has a denial of service vulnerability on DosFilter
Eclipse Jetty has a denial of service vulnerability on DosFilter
Description
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
Vulnerability details
The Jetty DoSFilter (Denial of Service Filter) is a security filter designed to protect web applications against certain types of Denial of Service (DoS) attacks and other abusive behavior. It helps to mitigate excessive resource consumption by limiting the rate at which clients can make requests to the server. The DoSFilter monitors and tracks client request patterns, including request rate
OSV
CVE-2024-9823: There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack
osv·2024-10-14·CVSS 7.5
CVE-2024-9823 [HIGH] CVE-2024-9823: There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
GHSA
Eclipse Jetty has a denial of service vulnerability on DosFilter
ghsa·2024-10-14
CVE-2024-9823 [MEDIUM] CWE-400 Eclipse Jetty has a denial of service vulnerability on DosFilter
Eclipse Jetty has a denial of service vulnerability on DosFilter
Description
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
Vulnerability details
The Jetty DoSFilter (Denial of Service Filter) is a security filter designed to protect web applications against certain types of Denial of Service (DoS) attacks and other abusive behavior. It helps to mitigate excessive resource consumption by limiting the rate at which clients can make requests to the server. The DoSFilter monitors and tracks client request patterns, including request rate
No detection rules found.
No public exploits indexed.
https://github.com/jetty/jetty.project/issues/1256https://github.com/jetty/jetty.project/security/advisories/GHSA-7hcf-ppf8-5w5hhttps://gitlab.eclipse.org/security/cve-assignement/-/issues/39https://lists.debian.org/debian-lts-announce/2025/04/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20250306-0006/
2024-10-14
Published