CVE-2024-6762

EUVD-2024-3125
Jetty PushSessionCacheFilter can be exploited by unauthenticated users 
to launch remote DoS attacks by exhausting the server’s memory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 58.62%
Affected Products (NVD)
VendorProductVersion
eclipsejetty
10.0.0 ≤
𝑥
< 10.0.18
eclipsejetty
11.0.0 ≤
𝑥
< 11.0.18
eclipsejetty
12.0.0 ≤
𝑥
< 12.0.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty9
bookworm
9.4.57-0+deb12u1
fixed
bookworm (security)
9.4.57-1.1~deb12u1
fixed
bullseye
vulnerable
bullseye (security)
9.4.57-0+deb11u3
fixed
forky
9.4.57-1.1
fixed
sid
9.4.57-1.1
fixed
trixie
9.4.57-1.1~deb13u1
fixed
trixie (security)
9.4.57-1.1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
jetty9
bionic
needed
focal
needed
jammy
needed
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
xenial
needed