Описание
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
jetty9 | fixed | 9.4.54-1 | package | |
jetty | removed | package |
Примечания
https://github.com/jetty/jetty.project/security/advisories/GHSA-r7m4-f9h5-gr79
https://github.com/jetty/jetty.project/pull/9715
https://github.com/jetty/jetty.project/pull/9716
https://github.com/jetty/jetty.project/pull/10756
https://github.com/jetty/jetty.project/pull/10755
EPSS
Связанные уязвимости
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Уязвимость контейнера сервлетов Eclipse Jetty, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS