CVE-2024-6762

EUVD-2024-3125
Jetty PushSessionCacheFilter can be exploited by unauthenticated users 
to launch remote DoS attacks by exhausting the server’s memory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
eclipseCNA
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
eclipsejetty
10.0.0 ≤
𝑥
< 10.0.18
eclipsejetty
11.0.0 ≤
𝑥
< 11.0.18
eclipsejetty
12.0.0 ≤
𝑥
< 12.0.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty9
bookworm
9.4.57-0+deb12u1
fixed
bookworm (security)
9.4.57-1.1~deb12u1
fixed
bullseye
vulnerable
bullseye (security)
9.4.57-0+deb11u3
fixed
forky
9.4.57-1.1
fixed
sid
9.4.57-1.1
fixed
trixie
9.4.57-1.1~deb13u1
fixed
trixie (security)
9.4.57-1.1~deb13u1
fixed