Jetty connection leaking on idle timeout when TCP congested
Published Feb 26, 2024
7.5
HIGHCVSS 3.1
EPSS 1.43%
Description
Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.
Affected products
-
- Version >= 10.0.0, <= 10.0.19StatusaffectedConstraints-
- Version >= 11.0.0, <= 11.0.19StatusaffectedConstraints-
- Version >= 12.0.0, <= 12.0.5StatusaffectedConstraints-
- Version >= 9.3.0, <= 9.4.53StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jetty | Jetty.project | n/a |
|
Configuration 1
Configuration 2
- 10.0
Configuration 3
- n/a
- n/a
- n/a
-
- Version 10.0.0StatusaffectedConstraints<=10.0.19
- Version 11.0.0StatusaffectedConstraints<=11.0.19
- Version 12.0.0StatusaffectedConstraints<=12.0.5
- Version 9.3.0StatusaffectedConstraints<=9.4.53
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jetty | Jetty.project | n/a |
|
OCP-Tools-4.12-RHEL-8
jenkins-0:2.440.3.1716445200-3.el8
Fixed · RHSA-2024:3635
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1716445211-1.el8
Fixed · RHSA-2024:3635
OCP-Tools-4.13-RHEL-8
jenkins-0:2.440.3.1716445150-3.el8
Fixed · RHSA-2024:3636
OCP-Tools-4.13-RHEL-8
jenkins-2-plugins-0:4.13.1716445207-1.el8
Fixed · RHSA-2024:3636
OCP-Tools-4.14-RHEL-8
jenkins-0:2.440.3.1716387933-3.el8
Fixed · RHSA-2024:3634
OCP-Tools-4.14-RHEL-8
jenkins-2-plugins-0:4.14.1716388016-1.el8
Fixed · RHSA-2024:3634
OCP-Tools-4.15-RHEL-8
jenkins-0:2.440.3.1718879390-3.el8
Fixed · RHSA-2024:4597
OCP-Tools-4.15-RHEL-8
jenkins-2-plugins-0:4.15.1718879538-1.el8
Fixed · RHSA-2024:4597
Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2
jetty
Fixed · RHSA-2024:4884
Red Hat build of Apicurio Registry 2.6.1 GA
jetty
Fixed · RHSA-2024:4873
OpenShift Serverless
jetty
Not affected
Red Hat Data Grid 8
jetty
Not affected
Red Hat Enterprise Linux 7
jetty
Out of support scope
Red Hat Fuse 7
jetty
Affected
Red Hat Integration Camel K 1
jetty
Will not fix
Red Hat Integration Camel Quarkus 2
jetty
Not affected
Red Hat JBoss Data Grid 7
jetty
Not affected
Red Hat JBoss Enterprise Application Platform 7
jetty
Not affected
Red Hat JBoss Enterprise Application Platform 8
jetty
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty
Affected
Red Hat OpenShift Container Platform 3.11
jenkins
Out of support scope
Red Hat Process Automation 7
jetty
Will not fix
Red Hat build of Apache Camel 4 for Quarkus 3
jetty
Not affected
Red Hat build of Apache Camel for Spring Boot 3
jetty
Out of support scope
streams for Apache Kafka
jetty
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| OCP-Tools-4.12-RHEL-8 | jenkins-0:2.440.3.1716445200-3.el8 | Fixed | RHSA-2024:3635 |
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1716445211-1.el8 | Fixed | RHSA-2024:3635 |
| OCP-Tools-4.13-RHEL-8 | jenkins-0:2.440.3.1716445150-3.el8 | Fixed | RHSA-2024:3636 |
| OCP-Tools-4.13-RHEL-8 | jenkins-2-plugins-0:4.13.1716445207-1.el8 | Fixed | RHSA-2024:3636 |
| OCP-Tools-4.14-RHEL-8 | jenkins-0:2.440.3.1716387933-3.el8 | Fixed | RHSA-2024:3634 |
| OCP-Tools-4.14-RHEL-8 | jenkins-2-plugins-0:4.14.1716388016-1.el8 | Fixed | RHSA-2024:3634 |
| OCP-Tools-4.15-RHEL-8 | jenkins-0:2.440.3.1718879390-3.el8 | Fixed | RHSA-2024:4597 |
| OCP-Tools-4.15-RHEL-8 | jenkins-2-plugins-0:4.15.1718879538-1.el8 | Fixed | RHSA-2024:4597 |
| Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2 | jetty | Fixed | RHSA-2024:4884 |
| Red Hat build of Apicurio Registry 2.6.1 GA | jetty | Fixed | RHSA-2024:4873 |
| OpenShift Serverless | jetty | Not affected | n/a |
| Red Hat Data Grid 8 | jetty | Not affected | n/a |
| Red Hat Enterprise Linux 7 | jetty | Out of support scope | n/a |
| Red Hat Fuse 7 | jetty | Affected | n/a |
| Red Hat Integration Camel K 1 | jetty | Will not fix | n/a |
| Red Hat Integration Camel Quarkus 2 | jetty | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | jetty | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jetty | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jetty | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins | Out of support scope | n/a |
| Red Hat Process Automation 7 | jetty | Will not fix | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | jetty | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | jetty | Out of support scope | n/a |
| streams for Apache Kafka | jetty | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The issue in Jetty where HTTP/2 connections can enter a congested, idle state and potentially exhaust server file descriptors represents a moderate severity due to its impact on system resources and service availability. While the vulnerability requires the deliberate creation of numerous congested connections by an attacker, its exploitation can lead to denial-of-service conditions by consuming all available file descriptors. This scenario could disrupt legitimate client connections and impair server responsiveness.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 1, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.43% (0.01433) | 72.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.43% (0.01433) | 69.50th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.45% (0.00448) | 62.78th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.23% (0.04228) | 87.64th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.27% (0.00269) | 50.05th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.82% (0.02816) | 84.89th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.49% (0.07492) | 86.01th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.82% (0.02816) | 85.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.70th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.04% (0.00045) | 15.31th | v3 (v2023.03.01) |
| Mar 30, 2024 | 0.04% (0.00045) | 13.29th | v3 (v2023.03.01) |
| Feb 27, 2024 | 0.04% (0.00043) | 6.84th | v3 (v2023.03.01) |
References (13)
- http://www.openwall.com/lists/oss-security/2024/03/20/2 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-22201 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2266136 Issue Tracking
- https://github.com/advisories/GHSA-rggv-cv7r-mw98 Advisory
- https://github.com/jetty/jetty.project/commit/0839a208cdc3fcfe25206a77af59ba9fda260188
- https://github.com/jetty/jetty.project/commit/b953871c9a5ff4fbca4a2499848f75182dbd9810
- https://github.com/jetty/jetty.project/issues/11256 x_refsource_MISCIssue Tracking
- https://github.com/jetty/jetty.project/issues/11259
- https://github.com/jetty/jetty.project/security/advisories/GHSA-rggv-cv7r-mw98 x_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00002.html Mailing List
- https://nvd.nist.gov/vuln/detail/CVE-2024-22201
- https://security.netapp.com/advisory/ntap-20240329-0001 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-22201
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/03/20/2 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2024-22201 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2266136 | Issue Tracking | |
| https://github.com/advisories/GHSA-rggv-cv7r-mw98 | Advisory | |
| https://github.com/jetty/jetty.project/commit/0839a208cdc3fcfe25206a77af59ba9fda260188 | ||
| https://github.com/jetty/jetty.project/commit/b953871c9a5ff4fbca4a2499848f75182dbd9810 | ||
| https://github.com/jetty/jetty.project/issues/11256 | x_refsource_MISCIssue Tracking | |
| https://github.com/jetty/jetty.project/issues/11259 | ||
| https://github.com/jetty/jetty.project/security/advisories/GHSA-rggv-cv7r-mw98 | x_refsource_CONFIRMVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00002.html | Mailing List | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-22201 | ||
| https://security.netapp.com/advisory/ntap-20240329-0001 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2024-22201 |
Change history (0)
No recorded changes yet.