« Volver al listado

CVE-2024-6762

Estado: ModificadaMedia (6.5)—

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6762",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6762",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-15T17:42:42.629742Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "emo@eclipse.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "emo@eclipse.org",
      "affectedData": [
        {
          "repo": "https://github.com/jetty/jetty.project",
          "vendor": "Eclipse Foundation",
          "modules": [
            "jetty-servlets"
          ],
          "product": "Jetty",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "10.0.17"
            },
            {
              "status": "affected",
              "version": "11.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "11.0.17"
            },
            {
              "status": "affected",
              "version": "12.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "12.0.3"
            }
          ],
          "packageName": "org.eclipse.jetty:jetty-servlets",
          "collectionURL": "https://repo.maven.apache.org/maven2/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-10-14T16:15:03.930",
  "references": [
    {
      "url": "https://github.com/jetty/jetty.project/pull/10755",
      "tags": [
        "Patch"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/pull/10756",
      "tags": [
        "Patch"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/pull/9715",
      "tags": [
        "Patch"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/pull/9716",
      "tags": [
        "Patch"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-r7m4-f9h5-gr79",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://gitlab.eclipse.org/security/cve-assignement/-/issues/24",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "emo@eclipse.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "emo@eclipse.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jetty PushSessionCacheFilter can be exploited by unauthenticated users \nto launch remote DoS attacks by exhausting the server’s memory."
    },
    {
      "lang": "es",
      "value": "Jetty PushSessionCacheFilter puede ser explotado por usuarios no autenticados para lanzar ataques DoS remotos agotando la memoria del servidor."
    }
  ],
  "lastModified": "2026-06-17T08:18:39.823",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "464A4A99-38E9-4ECD-AD6E-309AABC2F016",
              "versionEndExcluding": "10.0.18",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "823119A8-D743-4EFB-A35A-2821C5960139",
              "versionEndExcluding": "11.0.18",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE233C37-A184-44BC-B8C0-40F7B1E7512E",
              "versionEndExcluding": "12.0.4",
              "versionStartIncluding": "12.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "emo@eclipse.org"
}