Описание
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
A flaw was found in the Jetty-server package. This flaw allows an attacker to send invalid requests, causing a denial of service in the Jetty Server.
Отчет
In Red Hat Satellite 6.9 we are using 9.4.x or below of jetty-server. Red Hat Satellite 6.10 is not using jetty-server anymore. This flaw only affects versions above 10.0.x or 11.0.x of jetty-server, therefore Red Hat Satellite 6.9 or 6.10 are not impacted by this vulnerability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
A-MQ Clients 2 | jetty-server | Not affected | ||
Red Hat AMQ Broker 7 | jetty-server | Not affected | ||
Red Hat build of Apicurio Registry 2 | jetty-server | Not affected | ||
Red Hat build of Debezium 1 | jetty-server | Not affected | ||
Red Hat build of Quarkus | jetty-server | Not affected | ||
Red Hat Data Grid 8 | jetty-server | Not affected | ||
Red Hat Decision Manager 7 | jetty-server | Not affected | ||
Red Hat Fuse 7 | jetty-server | Not affected | ||
Red Hat Integration Camel K 1 | jetty-server | Not affected | ||
Red Hat Integration Camel Quarkus 1 | jetty-server | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 v ...
Jetty SslConnection does not release pooled ByteBuffers in case of errors
Уязвимость компонента SslConnections контейнера сервлетов Eclipse Jetty, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3