Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8184


There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.


Published

2024-10-14T16:15:04.380

Last Modified

2024-11-08T21:00:09.857

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse jetty < 9.4.56 Yes
Application eclipse jetty < 10.0.24 Yes
Application eclipse jetty < 11.0.24 Yes
Application eclipse jetty < 12.0.9 Yes

References