CVE-2024-9823

There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory finally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*

History

30 Jul 2025, 19:51

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
References () https://github.com/jetty/jetty.project/issues/1256 - () https://github.com/jetty/jetty.project/issues/1256 - Issue Tracking
References () https://github.com/jetty/jetty.project/security/advisories/GHSA-7hcf-ppf8-5w5h - () https://github.com/jetty/jetty.project/security/advisories/GHSA-7hcf-ppf8-5w5h - Vendor Advisory
References () https://gitlab.eclipse.org/security/cve-assignement/-/issues/39 - () https://gitlab.eclipse.org/security/cve-assignement/-/issues/39 - Issue Tracking, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20250306-0006/ - () https://security.netapp.com/advisory/ntap-20250306-0006/ - Third Party Advisory
First Time Netapp hci Compute Node
Netapp bootstrap Os
Eclipse jetty
Eclipse
Netapp active Iq Unified Manager
Netapp

07 Mar 2025, 01:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250306-0006/ -

Information

Published : 2024-10-14 15:15

Updated : 2025-07-30 19:51


NVD link : CVE-2024-9823

Mitre link : CVE-2024-9823

CVE.ORG link : CVE-2024-9823


JSON object : View

Products Affected

eclipse

  • jetty

netapp

  • bootstrap_os
  • active_iq_unified_manager
  • hci_compute_node
CWE
CWE-400

Uncontrolled Resource Consumption