VDB
Sign up
MEDIUM5.9

GHSA-g8m5-722r-8whq

Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks

Quick fix

GHSA-g8m5-722r-8whq — org.eclipse.jetty:jetty-server: upgrade to the fixed version with the command below.

# pom.xml: bump <version>12.0.9</version> for org.eclipse.jetty:jetty-server

Details

### Impact Remote DOS attack can cause out of memory

### Description There exists a security vulnerability in Jetty's `ThreadLimitHandler.getRemote()` which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.

### Affected Versions

* Jetty 12.0.0-12.0.8 (Supported) * Jetty 11.0.0-11.0.23 (EOL) * Jetty 10.0.0-10.0.23 (EOL) * Jetty 9.3.12-9.4.55 (EOL)

### Patched Versions

* Jetty 12.0.9 * Jetty 11.0.24 * Jetty 10.0.24 * Jetty 9.4.56

### Workarounds

Do not use `ThreadLimitHandler`. Consider use of `QoSHandler` instead to artificially limit resource utilization.

### References

Jetty 12 - https://github.com/jetty/jetty.project/pull/11723

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.eclipse.jetty:jetty-server
Introduced in: 12.0.0Fixed in: 12.0.9
Fix# pom.xml: bump <version>12.0.9</version> for org.eclipse.jetty:jetty-server
Maven/org.eclipse.jetty:jetty-server
Introduced in: 10.0.0Fixed in: 10.0.24
Fix# pom.xml: bump <version>10.0.24</version> for org.eclipse.jetty:jetty-server
Maven/org.eclipse.jetty:jetty-server
Introduced in: 11.0.0Fixed in: 11.0.24
Fix# pom.xml: bump <version>11.0.24</version> for org.eclipse.jetty:jetty-server
Maven/org.eclipse.jetty:jetty-server
Introduced in: 9.3.12Fixed in: 9.4.56
Fix# pom.xml: bump <version>9.4.56</version> for org.eclipse.jetty:jetty-server

References