Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-7708

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Версия от 10.0.7 (включая) до 10.0.23 (исключая)
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
Версия от 11.0.7 (включая) до 11.0.23 (исключая)

EPSS

Процентиль: 37%
0.0044
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVSS3: 7.5
redhat
около 2 месяцев назад

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVSS3: 7.5
debian
около 2 месяцев назад

For requests that have a body, but reading the body may end up in read ...

CVSS3: 7.5
github
около 1 месяца назад

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

EPSS

Процентиль: 37%
0.0044
Низкий

7.5 High

CVSS3

Дефекты

CWE-400