Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-13009

Опубликовано: 08 мая 2025
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.

A flaw was found in Eclipse Jetty. This vulnerability allows corrupted and inadvertent data sharing between requests via a gzip error when inflating a request body. If the request body is malformed, the gzip decompression process can fail, resulting in the application inadvertently using data from a previous request when processing the current one.

Отчет

This vulnerability is rated as an IMPORTANT severity because a buffer management vulnerability exists within the GzipHandler's buffer release mechanism when encountering gzip errors during request body inflation, this flaw can lead to the incorrect release and subsequent inadvertent sharing and corruption of request body data between concurrent uncompressed requests, results in data exposure and incorrect processing of requests due to corrupted input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2jetty-serverAffected
OpenShift Developer Tools and ServicesjenkinsNot affected
Red Hat AMQ Broker 7jetty-serverNot affected
Red Hat build of Apache Camel - HawtIO 4jetty-serverNot affected
Red Hat build of Apicurio Registry 2jetty-serverNot affected
Red Hat build of Apicurio Registry 3jetty-serverNot affected
Red Hat build of Debezium 2jetty-serverWill not fix
Red Hat build of Debezium 3jetty-serverWill not fix
Red Hat Data Grid 8jetty-serverAffected
Red Hat Enterprise Linux 7maven-wagonOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-404
https://bugzilla.redhat.com/show_bug.cgi?id=2365135jetty-server: Jetty: Gzip Request Body Buffer Corruption

EPSS

Процентиль: 11%
0.0004
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
4 месяца назад

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.

CVSS3: 7.2
nvd
4 месяца назад

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.

CVSS3: 7.2
debian
4 месяца назад

In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly ...

CVSS3: 7.2
github
4 месяца назад

**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request

CVSS3: 7.2
fstec
4 месяца назад

Уязвимость контейнера сервлетов Eclipse Jetty, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю обойти внедренные ограничения безопасности

EPSS

Процентиль: 11%
0.0004
Низкий

7.2 High

CVSS3