Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9823


There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.


Published

2024-10-14T15:15:14.560

Last Modified

2025-07-30T19:51:05.457

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse jetty < 9.4.54 Yes
Application eclipse jetty < 10.0.18 Yes
Application eclipse jetty < 11.0.18 Yes
Application eclipse jetty < 12.0.3 Yes
Operating System netapp bootstrap_os - Yes
Hardware netapp hci_compute_node - No
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes

References