Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-22201

Опубликовано: 26 фев. 2024
Источник: redhat
CVSS3: 7.5

Описание

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

A flaw was found in Jetty, a Java based web server and servlet engine. If an HTTP/2 connection gets TCP congested, it remains open and idle, and connections may be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients.

Отчет

The issue in Jetty where HTTP/2 connections can enter a congested, idle state and potentially exhaust server file descriptors represents a moderate severity due to its impact on system resources and service availability. While the vulnerability requires the deliberate creation of numerous congested connections by an attacker, its exploitation can lead to denial-of-service conditions by consuming all available file descriptors. This scenario could disrupt legitimate client connections and impair server responsiveness.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift ServerlessjettyNot affected
Red Hat build of Apache Camel 4 for Quarkus 3jettyNot affected
Red Hat build of Apache Camel for Spring Boot 3jettyOut of support scope
Red Hat Data Grid 8jettyNot affected
Red Hat Enterprise Linux 7jettyOut of support scope
Red Hat Fuse 7jettyAffected
Red Hat Integration Camel K 1jettyWill not fix
Red Hat Integration Camel Quarkus 2jettyNot affected
Red Hat JBoss Data Grid 7jettyNot affected
Red Hat JBoss Enterprise Application Platform 7jettyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2266136jetty: stop accepting new connections from valid clients

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

CVSS3: 7.5
nvd
больше 1 года назад

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

CVSS3: 7.5
debian
больше 1 года назад

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL con ...

suse-cvrf
больше 1 года назад

Security update for jetty-minimal

CVSS3: 7.5
redos
около 1 года назад

Уязвимость Jetty

7.5 High

CVSS3

Уязвимость CVE-2024-22201