Vulnerability Description
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Jetty | >= 9.4.0, < 9.4.57 |
Related Weaknesses (CWE)
References
- https://github.com/jetty/jetty.project/security/advisories/GHSA-q4rv-gq96-w7c5Vendor Advisory
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/48Issue Tracking
FAQ
What is CVE-2024-13009?
CVE-2024-13009 is a vulnerability with a CVSS score of 7.2 (HIGH). In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing ...
How severe is CVE-2024-13009?
CVE-2024-13009 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-13009?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Jetty.