PT-2024-3054 · Eclipse+4 · Jetty+4

Luffy1949

·

Published

2024-02-26

·

Updated

2026-01-19

·

CVE-2024-22201

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Jetty versions prior to 9.4.54 Jetty versions prior to 10.0.20 Jetty versions prior to 11.0.20 Jetty versions prior to 12.0.6
Description The issue is related to an HTTP/2 SSL connection that is established and TCP congested, which will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The client may also be impacted if the server does not read, causing a TCP congestion, but the issue is more severe for servers.
Recommendations For versions prior to 9.4.54, update to version 9.4.54 or later. For versions prior to 10.0.20, update to version 10.0.20 or later. For versions prior to 11.0.20, update to version 11.0.20 or later. For versions prior to 12.0.6, update to version 12.0.6 or later. As a temporary workaround, consider disabling HTTP/2 and HTTP/3 support until you can upgrade to a patched version of Jetty. Note that HTTP/1.x is not affected.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-16002
ALT-PU-2024-16022
ALT-PU-2024-16072
BDU:2024-03239
CVE-2024-22201
DLA-3780-1
DSA-5664-1
GHSA-RGGV-CV7R-MW98
OPENSUSE-SU-2024:13724-1
RHSA-2024:3634
RHSA-2024:3635
RHSA-2024:3636
RHSA-2024:4597
SUSE-SU-2024:0817-1
SUSE-SU-2024_0817-1

Affected Products

Alt Linux
Astra Linux
Jetty
Red Os
Suse