Eclipse Jetty是Eclipse基金会的一个开源的、基于Java的Web服务器和Java Servlet容器。 Eclipse Jetty存在安全漏洞,该漏洞源于未授权用户可以通过发送精心构造的请求来触发远程拒绝服务攻击,最终导致服务器内存耗尽。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Jetty | 9.0.0 ~ 9.4.54 | - |
|
| Eclipse Jetty | Jetty | 12.0.0 ~ 12.0.3 | - |
|
| Eclipse Jetty | Jetty | 12.0.0 ~ 12.0.3 | - |
|
| Eclipse Jetty | Jetty | 12.0.0 ~ 12.0.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-8184 | 5.9 MEDIUM | Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks |
| CVE-2024-6763 | 3.7 LOW | Jetty URI parsing of invalid authority |
| CVE-2024-6762 | 3.1 LOW | Jetty PushSessionCacheFilter can cause remote DoS attacks |
No comments yet