There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jetty-jaasUpgrade jetty-plusUpgrade jetty-servletUpgrade jetty-clientUpgrade jetty-projectUpgrade jetty-securityUpgrade jetty-websocket-serverUpgrade jetty-websocket-commonUpgrade jetty-jspUpgrade jetty-deployUpgrade jetty-monitorUpgrade jetty-websocket-clientUpgrade jetty-jspc-maven-pluginUpgrade jetty-websocket-parentUpgrade jetty-ioUpgrade jetty-antUpgrade jetty-proxyUpgrade jetty-maven-pluginUpgrade jetty-utilUpgrade jetty-annotationsUpgrade jetty-rewriteUpgrade jetty-util-ajaxUpgrade jetty-xmlUpgrade jetty-websocket-apiUpgrade jetty-webappUpgrade jetty-startUpgrade jetty-jndiUpgrade jetty-javadocUpgrade jetty-continuationUpgrade jetty-jaspiUpgrade jetty-websocket-servletUpgrade jetty-jmxUpgrade jetty-serverUpgrade jetty-servletsUpgrade jetty-runnerUpgrade jetty-http | Dec 20, 2024 | Oct 14, 2024 |
| Debian | — | Upgrade jetty9 | Apr 3, 2025 | Oct 14, 2024 |
| Ubuntu | — | No solution exists | Jul 1, 2025 | Oct 14, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub