PT-2024-9612 · Eclipse+2 · Eclipse Jetty+2

Lian Kee

+1

·

Published

2024-10-14

·

Updated

2026-05-18

·

CVE-2024-9823

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions prior to 9.4.54 Eclipse Jetty versions prior to 10.0.18 Eclipse Jetty versions prior to 11.0.18 Eclipse Jetty versions prior to 12.0.3
Description The vulnerability in Jetty's DosFilter can be exploited by unauthorized users to cause a remote denial-of-service (DoS) attack on the server. By repeatedly sending crafted requests, attackers can trigger OutOfMemory errors and exhaust the server's memory. The DoSFilter is designed to protect web applications against certain types of DoS attacks, but its internal tracking of requests is the source of this OutOfMemory condition. Users of the DoSFilter may be subject to DoS attacks that will ultimately exhaust the memory of the server if they have not configured session passivation or an aggressive session inactivation timeout.
Recommendations For Eclipse Jetty versions prior to 9.4.54, update to version 9.4.54 or later. For Eclipse Jetty versions prior to 10.0.18, update to version 10.0.18 or later. For Eclipse Jetty versions prior to 11.0.18, update to version 11.0.18 or later. For Eclipse Jetty versions prior to 12.0.3, update to version 12.0.3 or later. As a temporary workaround, consider configuring session passivation or an aggressive session inactivation timeout to mitigate the risk of exploitation.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-11324
CLEANSTART-2026-DD05788
CLEANSTART-2026-GH89210
CLEANSTART-2026-VH41554
CVE-2024-9823
DLA-4106-1
DLA-4106-2
DSA-5894-1
GHSA-7HCF-PPF8-5W5H
GHSA-J26W-F9RQ-MR2Q

Affected Products

Debian
Eclipse Jetty
Red Os