Eclipse Jetty是Eclipse基金会的一个开源的、基于Java的Web服务器和Java Servlet容器。 Eclipse Jetty 7.0.0到12.0.11版本存在安全漏洞,该漏洞源于HttpURI类对URI的authority部分进行不足的验证,可能会导致开放重定向攻击或服务端请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Jetty | 7.0.0 ~ 12.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-8184 | 5.9 MEDIUM | Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| CVE-2024-9823 | 5.3 MEDIUM | Jetty DOS vulnerability on DosFilter |
| CVE-2024-6762 | 3.1 LOW | Jetty PushSessionCacheFilter can cause remote DoS attacks |
No comments yet