CVE-2024-9823

MEDIUM

Eclipse Jetty 9.0.0-9.4.53 and 12.0.0-12.0.2 - Unauthenticated Denial of Service via DosFilter Memory Exhaustion

Title source: llm
STIX 2.1

Description

There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.

Scores

CVSS v3 5.3
EPSS 0.0068
EPSS Percentile 71.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (7)
eclipse/jetty 9.0.0 - 9.4.54
netapp/active_iq_unified_manager (3 CPE variants)
netapp/bootstrap_os
org.eclipse.jetty/jetty-servlets 9.0.0 - 9.4.54Maven
org.eclipse.jetty.ee10/jetty-ee10-servlets 12.0.0 - 12.0.3Maven
org.eclipse.jetty.ee8/jetty-ee8-servlets 12.0.0 - 12.0.3Maven
org.eclipse.jetty.ee9/jetty-ee9-servlets 12.0.0 - 12.0.3Maven
Published Oct 14, 2024
Tracked Since Feb 18, 2026