CVE-2024-22201
Published: Feb 26, 2024
Modified: Feb 13, 2025
CVSS v3.1
7.5
Description
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.
| Vendor | Product | Versions |
|---|---|---|
jetty | jetty.project | affected >= 9.3.0, <= 9.4.53affected >= 10.0.0, <= 10.0.19affected >= 11.0.0, <= 11.0.19affected >= 12.0.0, <= 12.0.5 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now