Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 28, 2011 |
| Suse | — | Upgrade jetty5-javadocUpgrade jetty5Upgrade jetty5-demoUpgrade jetty5-manual | Dec 12, 2013 | Dec 29, 2011 |
| Ubuntu | — | Upgrade libjetty-java | Nov 8, 2024 | Dec 30, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub