Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-7708

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted HTTP requests. Specifically, a buffer leak occurs when processing requests that have a body but read zero bytes, such as 100-Continue requests, or during slow network conditions. This can lead to resource exhaustion and make the server unavailable.

Отчет

Red Hat's version of Eclipse Jetty (9.0.3) shipped in Red Hat Enterprise Linux 7 is not affected by this vulnerability. The flaw was introduced in Jetty 10.0.0 and affects versions 10.0.0 through 10.0.22 and 11.0.0 through 11.0.22. The shipped version predates the introduction of the vulnerable code.

Меры по смягчению последствий

No mitigation is needed as Red Hat products are not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7jettyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2499935jetty: Eclipse Jetty: Denial of Service due to buffer leak in handling certain HTTP requests

EPSS

Процентиль: 37%
0.0044
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVSS3: 7.5
nvd
около 2 месяцев назад

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVSS3: 7.5
debian
около 2 месяцев назад

For requests that have a body, but reading the body may end up in read ...

CVSS3: 7.5
github
около 1 месяца назад

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

EPSS

Процентиль: 37%
0.0044
Низкий

7.5 High

CVSS3