Eclipse Jetty是Eclipse基金会的一个开源的、基于Java的Web服务器和Java Servlet容器。 Eclipse Jetty存在安全漏洞,该漏洞源于未经授权的用户可以通过发送精心构造的请求来触发该漏洞,导致服务器出现内存溢出错误并耗尽服务器内存,从而引发远程拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Jetty | 9.3.12 ~ 9.4.55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-9823 | 5.3 MEDIUM | Jetty DOS vulnerability on DosFilter |
| CVE-2024-6763 | 3.7 LOW | Jetty URI parsing of invalid authority |
| CVE-2024-6762 | 3.1 LOW | Jetty PushSessionCacheFilter can cause remote DoS attacks |
No comments yet