Jetty DOS vulnerability on DosFilter
Published Oct 14, 2024
7.5
HIGHCVSS 3.1
EPSS 0.94%
Description
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
Affected products
-
- Version 10.0.0StatusaffectedConstraints<10.0.18
- Version 11.0.0StatusaffectedConstraints<11.0.18
- Version 9.0.0StatusaffectedConstraints<9.4.54
- Version
-
- Version 12.0.0StatusaffectedConstraints<12.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Eclipse Foundation | Jetty | unaffected |
| ||||||||||||
| Eclipse Jetty | Jetty | unaffected |
|
Configuration 1
Configuration 2
- n/a
Running on/with
- n/a
Configuration 3
- n/a
- n/a
- n/a
-
- Version 10.0.0StatusaffectedConstraints<10.0.18
- Version 11.0.0StatusaffectedConstraints<11.0.18
- Version 12.0.0StatusaffectedConstraints<12.0.3
- Version 9.0.0StatusaffectedConstraints<9.4.54
- Version
Streams for Apache Kafka 2.8.0
jetty-servlets
Fixed · RHSA-2024:9571
OpenShift Serverless
jetty-servlets
Not affected
Red Hat Build of Keycloak
jetty-servlets
Will not fix
Red Hat Data Grid 8
jetty-servlets
Not affected
Red Hat Fuse 7
jetty-servlets
Out of support scope
Red Hat Integration Camel K 1
jetty-servlets
Will not fix
Red Hat JBoss Data Grid 7
jetty-servlets
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jetty-servlets
Not affected
Red Hat JBoss Enterprise Application Platform 8
jetty-servlets
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jetty-servlets
Affected
Red Hat Process Automation 7
jetty-servlets
Will not fix
Red Hat Single Sign-On 7
jetty-servlets
Will not fix
Red Hat build of Apicurio Registry 2
org.eclipse.jetty/jetty-servlets
Not affected
Red Hat build of Debezium 2
jetty-servlets
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Streams for Apache Kafka 2.8.0 | jetty-servlets | Fixed | RHSA-2024:9571 |
| OpenShift Serverless | jetty-servlets | Not affected | n/a |
| Red Hat Build of Keycloak | jetty-servlets | Will not fix | n/a |
| Red Hat Data Grid 8 | jetty-servlets | Not affected | n/a |
| Red Hat Fuse 7 | jetty-servlets | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | jetty-servlets | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | jetty-servlets | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jetty-servlets | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jetty-servlets | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jetty-servlets | Affected | n/a |
| Red Hat Process Automation 7 | jetty-servlets | Will not fix | n/a |
| Red Hat Single Sign-On 7 | jetty-servlets | Will not fix | n/a |
| Red Hat build of Apicurio Registry 2 | org.eclipse.jetty/jetty-servlets | Not affected | n/a |
| Red Hat build of Debezium 2 | jetty-servlets | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
The DoSFilter can be configured to not use sessions for tracking usage by setting the trackSessions init parameter to false. This will then use only the IP tracking mechanism, which is not vulnerable.
Sessions can also be configured to have aggressive passivation or inactivation limits.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Oct 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.94% (0.00940) | 59.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.95% (0.00946) | 56.34th | v5 (v2026.06.15) |
| Oct 1, 2025 | 1.16% (0.01162) | 77.96th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.14% (0.00139) | 31.32th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.70th | v3 (v2023.03.01) |
| Oct 15, 2024 | 0.04% (0.00045) | 16.44th | v3 (v2023.03.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2024-9823 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2318565 Issue Tracking
- https://github.com/advisories/GHSA-j26w-f9rq-mr2q Advisory
- https://github.com/jetty/jetty.project/issues/1256 Issue Tracking
- https://github.com/jetty/jetty.project/security/advisories/GHSA-7hcf-ppf8-5w5h Vendor Advisory
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/39 Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-9823
- https://security.netapp.com/advisory/ntap-20250306-0006 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-9823
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-9823 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2318565 | Issue Tracking | |
| https://github.com/advisories/GHSA-j26w-f9rq-mr2q | Advisory | |
| https://github.com/jetty/jetty.project/issues/1256 | Issue Tracking | |
| https://github.com/jetty/jetty.project/security/advisories/GHSA-7hcf-ppf8-5w5h | Vendor Advisory | |
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/39 | Issue TrackingVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-9823 | ||
| https://security.netapp.com/advisory/ntap-20250306-0006 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2024-9823 |
Change history (0)
No recorded changes yet.