← Back

CVE-2024-8184

nvd nist
Published: Oct 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.

Affected (4)

Products: Eclipse: Jetty
1 product
Jetty
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
From 10.0.0 to 10.0.24
From 11.0.0 to 11.0.24
From 12.0.0 to 12.0.9
From 9.3.12 to 9.4.56

Timeline

No history available yet.