Loading vulnerability details...
Remote DOS attack can cause out of memory
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which
can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By
repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the
server's memory.
Do not use ThreadLimitHandler.
Consider use of QoSHandler instead to artificially limit resource utilization.
Jetty 12 - https://github.com/jetty/jetty.project/pull/11723
Remote DOS attack can cause out of memory
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which
can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By
repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the
server's memory.
Do not use ThreadLimitHandler.
Consider use of QoSHandler instead to artificially limit resource utilization.
Jetty 12 - https://github.com/jetty/jetty.project/pull/11723
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Probability of exploitation in the next 30 days · more likely than 62.7% of all CVEs.
Apply security patches to version 12.0.9 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior