Описание
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.
This is particularly the case for 100-Continue, but any request where the network is slow can leak.
A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted HTTP requests. Specifically, a buffer leak occurs when processing requests that have a body but read zero bytes, such as 100-Continue requests, or during slow network conditions. This can lead to resource exhaustion and make the server unavailable.
Отчет
Red Hat's version of Eclipse Jetty (9.0.3) shipped in Red Hat Enterprise Linux 7 is not affected by this vulnerability. The flaw was introduced in Jetty 10.0.0 and affects versions 10.0.0 through 10.0.22 and 11.0.0 through 11.0.22. The shipped version predates the introduction of the vulnerable code.
Меры по смягчению последствий
No mitigation is needed as Red Hat products are not affected by this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | jetty | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.
For requests that have a body, but reading the body may end up in read ...
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
EPSS
7.5 High
CVSS3