Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3720-1

Опубликовано: 18 окт. 2024
Источник: suse-cvrf

Описание

Security update for jetty-minimal

This update for jetty-minimal fixes the following issues:

  • CVE-2024-8184: Fixed remote denial-of-service in ThreadLimitHandler.getRemote() (bsc#1231651).

Список пакетов

SUSE Linux Enterprise Module for Development Tools 15 SP5
jetty-http-9.4.56-150200.3.28.1
jetty-io-9.4.56-150200.3.28.1
jetty-security-9.4.56-150200.3.28.1
jetty-server-9.4.56-150200.3.28.1
jetty-servlet-9.4.56-150200.3.28.1
jetty-util-9.4.56-150200.3.28.1
jetty-util-ajax-9.4.56-150200.3.28.1
SUSE Linux Enterprise Module for Development Tools 15 SP6
jetty-http-9.4.56-150200.3.28.1
jetty-io-9.4.56-150200.3.28.1
jetty-security-9.4.56-150200.3.28.1
jetty-server-9.4.56-150200.3.28.1
jetty-servlet-9.4.56-150200.3.28.1
jetty-util-9.4.56-150200.3.28.1
jetty-util-ajax-9.4.56-150200.3.28.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
jetty-continuation-9.4.56-150200.3.28.1
openSUSE Leap 15.5
jetty-annotations-9.4.56-150200.3.28.1
jetty-ant-9.4.56-150200.3.28.1
jetty-cdi-9.4.56-150200.3.28.1
jetty-client-9.4.56-150200.3.28.1
jetty-continuation-9.4.56-150200.3.28.1
jetty-deploy-9.4.56-150200.3.28.1
jetty-fcgi-9.4.56-150200.3.28.1
jetty-http-9.4.56-150200.3.28.1
jetty-http-spi-9.4.56-150200.3.28.1
jetty-io-9.4.56-150200.3.28.1
jetty-jaas-9.4.56-150200.3.28.1
jetty-jmx-9.4.56-150200.3.28.1
jetty-jndi-9.4.56-150200.3.28.1
jetty-jsp-9.4.56-150200.3.28.1
jetty-minimal-javadoc-9.4.56-150200.3.28.1
jetty-openid-9.4.56-150200.3.28.1
jetty-plus-9.4.56-150200.3.28.1
jetty-proxy-9.4.56-150200.3.28.1
jetty-quickstart-9.4.56-150200.3.28.1
jetty-rewrite-9.4.56-150200.3.28.1
jetty-security-9.4.56-150200.3.28.1
jetty-server-9.4.56-150200.3.28.1
jetty-servlet-9.4.56-150200.3.28.1
jetty-servlets-9.4.56-150200.3.28.1
jetty-start-9.4.56-150200.3.28.1
jetty-util-9.4.56-150200.3.28.1
jetty-util-ajax-9.4.56-150200.3.28.1
jetty-webapp-9.4.56-150200.3.28.1
jetty-xml-9.4.56-150200.3.28.1
openSUSE Leap 15.6
jetty-annotations-9.4.56-150200.3.28.1
jetty-ant-9.4.56-150200.3.28.1
jetty-cdi-9.4.56-150200.3.28.1
jetty-client-9.4.56-150200.3.28.1
jetty-continuation-9.4.56-150200.3.28.1
jetty-deploy-9.4.56-150200.3.28.1
jetty-fcgi-9.4.56-150200.3.28.1
jetty-http-9.4.56-150200.3.28.1
jetty-http-spi-9.4.56-150200.3.28.1
jetty-io-9.4.56-150200.3.28.1
jetty-jaas-9.4.56-150200.3.28.1
jetty-jmx-9.4.56-150200.3.28.1
jetty-jndi-9.4.56-150200.3.28.1
jetty-jsp-9.4.56-150200.3.28.1
jetty-minimal-javadoc-9.4.56-150200.3.28.1
jetty-openid-9.4.56-150200.3.28.1
jetty-plus-9.4.56-150200.3.28.1
jetty-proxy-9.4.56-150200.3.28.1
jetty-quickstart-9.4.56-150200.3.28.1
jetty-rewrite-9.4.56-150200.3.28.1
jetty-security-9.4.56-150200.3.28.1
jetty-server-9.4.56-150200.3.28.1
jetty-servlet-9.4.56-150200.3.28.1
jetty-servlets-9.4.56-150200.3.28.1
jetty-start-9.4.56-150200.3.28.1
jetty-util-9.4.56-150200.3.28.1
jetty-util-ajax-9.4.56-150200.3.28.1
jetty-webapp-9.4.56-150200.3.28.1
jetty-xml-9.4.56-150200.3.28.1

Описание

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.


Затронутые продукты
SUSE Linux Enterprise Module for Development Tools 15 SP5:jetty-http-9.4.56-150200.3.28.1
SUSE Linux Enterprise Module for Development Tools 15 SP5:jetty-io-9.4.56-150200.3.28.1
SUSE Linux Enterprise Module for Development Tools 15 SP5:jetty-security-9.4.56-150200.3.28.1
SUSE Linux Enterprise Module for Development Tools 15 SP5:jetty-server-9.4.56-150200.3.28.1

Ссылки
Уязвимость SUSE-SU-2024:3720-1