cbcvebase.

Debian Jetty9 vulnerabilities

35 known vulnerabilities affecting debian/jetty9.

Total CVEs
35
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH9MEDIUM12LOW13

Vulnerabilities

Page 1 of 2
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in dnsdist 1.8.2-2 (forky)2023
CVE-2023-44487 [HIGH] CVE-2023-44487: dnsdist - The HTTP/2 protocol allows a denial of service (server resource consumption) bec... The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.8.2-2) sid: resolved (fixed in 1.8.2-2) trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2021-34429P1MEDIUMCVSS 5.3ExploitedPoCfixed in jetty9 9.4.39-3 (bookworm)2021
CVE-2021-34429 [MEDIUM] CVE-2021-34429: jetty9 - For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs ca... For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5. Scope: local bookworm: resolved (fixed in 9.4.39-3) bullseye: resol
debian
CVE-2021-28169P2MEDIUMCVSS 5.3ExploitedPoCfixed in jetty9 9.4.39-2 (bookworm)2021
CVE-2021-28169 [MEDIUM] CVE-2021-28169: jetty9 - For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for r... For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web applicat
debian
CVE-2021-28164P2MEDIUMCVSS 5.3PoCfixed in jetty9 9.4.39-1 (bookworm)2021
CVE-2021-28164 [MEDIUM] CVE-2021-28164: jetty9 - In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mo... In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web a
debian
CVE-2017-7657P2LOWCVSS 9.8fixed in jetty9 9.2.25-1 (bookworm)2017
CVE-2017-7657 [CRITICAL] CVE-2017-7657: jetty9 - In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.... In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interp
debian
CVE-2017-7658P2LOWCVSS 9.8fixed in jetty9 9.2.25-1 (bookworm)2017
CVE-2017-7658 [CRITICAL] CVE-2017-7658: jetty9 - In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x confi... In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter
debian
CVE-2021-28165P3HIGHCVSS 7.5fixed in jetty9 9.4.39-1 (bookworm)2021
CVE-2021-28165 [HIGH] CVE-2021-28165: jetty9 - In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to ... In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. Scope: local bookworm: resolved (fixed in 9.4.39-1) bullseye: resolved (fixed in 9.4.39-1) forky: resolved (fixed in 9.4.39-1) sid: resolved (fixed in 9.4.39-1) trixie: resolved (fixed in 9.4.39-1)
debian
CVE-2019-17638P2CRITICALCVSS 9.4fixed in jetty9 9.4.31-1 (bookworm)2019
CVE-2019-17638 [CRITICAL] CVE-2019-17638: jetty9 - In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too ... In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice. Because of this double release, two threads can acquire the same ByteBuffer from the poo
debian
CVE-2020-27223P3MEDIUMCVSS 5.2fixed in jetty9 9.4.38-1 (bookworm)2020
CVE-2020-27223 [MEDIUM] CVE-2020-27223: jetty9 - In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11... In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing th
debian
CVE-2017-9735P3HIGHCVSS 7.5fixed in jetty9 9.2.22-1 (bookworm)2017
CVE-2017-9735 [HIGH] CVE-2017-9735: jetty9 - Jetty through 9.4.x is prone to a timing channel in util/security/Password.java,... Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. Scope: local bookworm: resolved (fixed in 9.2.22-1) bullseye: resolved (fixed in 9.2.22-1) forky: resolved (fixed in 9.2.22-1) sid: resolved (fixed in 9.2.22-1) t
debian
CVE-2017-7656P3LOWCVSS 7.5fixed in jetty9 9.2.25-1 (bookworm)2017
CVE-2017-7656 [HIGH] CVE-2017-7656: jetty9 - In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.... In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted
debian
CVE-2025-5115P3HIGHCVSS 7.7fixed in jetty12 12.0.17-3.1 (forky)2025
CVE-2025-5115 [HIGH] CVE-2025-5115: jetty12 - In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.a... In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a str
debian
CVE-2023-36478P3HIGHCVSS 7.5fixed in jetty9 9.4.50-4+deb12u2 (bookworm)2023
CVE-2023-36478 [HIGH] CVE-2023-36478: jetty9 - Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 th... Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit. `MetaDataBuilder.java` determines if a header name or value exceeds the size limit, and throws an exception
debian
CVE-2024-22201P3HIGHCVSS 7.5fixed in jetty9 9.4.50-4+deb12u3 (bookworm)2024
CVE-2024-22201 [HIGH] CVE-2024-22201: jetty9 - Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection th... Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is pa
debian
CVE-2025-1948P3HIGHCVSS 7.5fixed in jetty12 12.0.17-1 (forky)2025
CVE-2025-1948 [HIGH] CVE-2025-1948: jetty12 - In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can speci... In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the specified capacity to encode HTTP responses, likely resulting in OutOfMemoryError being thro
debian
CVE-2024-13009P3LOWCVSS 7.2fixed in jetty9 9.4.57-0+deb12u1 (bookworm)2024
CVE-2024-13009 [HIGH] CVE-2024-13009: jetty12 - In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released w... In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests. Scope: local forky: resolved sid: resolved trixie: resolved
debian
CVE-2020-27216P3HIGHCVSS 7.0fixed in jetty9 9.4.33-1 (bookworm)2020
CVE-2020-27216 [HIGH] CVE-2020-27216: jetty9 - In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.b... In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creatio
debian
CVE-2022-2048P3HIGHCVSS 7.5fixed in jetty9 9.4.48-1 (bookworm)2022
CVE-2022-2048 [HIGH] CVE-2022-2048: jetty9 - In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP... In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests. Scope: local bookworm: resolved (fixed in 9.4.
debian
CVE-2024-9823P3MEDIUMCVSS 5.3fixed in jetty9 9.4.57-0+deb12u1 (bookworm)2024
CVE-2024-9823 [MEDIUM] CVE-2024-9823: jetty9 - There exists a security vulnerability in Jetty's DosFilter which can be exploite... There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally. Scope: local bookworm: resolved (fixed in 9.4.57-0+deb12u1) bulls
debian
CVE-2019-10241P3MEDIUMCVSS 6.1fixed in jetty9 9.4.18-2 (bookworm)2019
CVE-2019-10241 [MEDIUM] CVE-2019-10241: jetty9 - In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and olde... In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents. Scope: local bookworm: resolved (fixed in 9.4.18-2) bullseye: resolved (fixed in
debian
Debian Jetty9 vulnerabilities | cvebase