← Back

CVE-2024-22201

nvd nist
Published: Feb 26, 2024Modified: Feb 13, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

Affected (8)

1 product
Jetty
1 product
Debian Linux
2 products
Active Iq Unified Manager
Bluexp
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
From 10.0.0 to 10.0.20
From 11.0.0 to 11.0.20
From 12.0.0 to 12.0.6
From 9.3.0 to 9.4.54
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions

References (10)

Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Mailing List
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.