CVE-2024-7708

EUVD-2024-55651
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.
This is particularly the case for 100-Continue, but any request where the network is slow can leak.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 36.51%
Affected Products (NVD)
VendorProductVersion
eclipsejetty
10.0.7 ≤
𝑥
< 10.0.23
eclipsejetty
11.0.7 ≤
𝑥
< 11.0.23
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty12
forky
undetermined
sid
undetermined
trixie
undetermined
trixie (security)
undetermined
jetty9
bookworm
undetermined
bookworm (security)
undetermined
bullseye
undetermined
bullseye (security)
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
trixie (security)
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty12
jammy
dne
noble
dne
resolute
needs-triage
jetty9
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage