Lucene search

K
redosRedosROS-20240729-10
HistoryJul 29, 2024 - 12:00 a.m.

ROS-20240729-10

2024-07-2900:00:00
redos.red-soft.ru
6
eclipse jetty
httpservletrequest
vulnerability
denial of service
remote attacker
cookie injection
servlet container
unlimited memory
syntax correctness errors
unix

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.9

Confidence

Low

Vulnerability in HttpServletRequest.getParameter() andHttpServletRequest.getParts() functions of servlet container
Eclipse Jetty is related to the allocation of unlimited memory. Exploitation of the vulnerability could allow
an attacker acting remotely to cause a denial of service

The Eclipse Jetty servlet container vulnerability is related to syntax correctness errors.
input. Exploitation of the vulnerability could allow a remote attacker to inject some cookies
inside others and affect their processing

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64jetty<ย 9.4.54-1UNKNOWN

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.9

Confidence

Low