First published: Thu May 08 2025(Updated: )
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mortbay Jetty | >=9.4.0<=9.4.56 | |
maven/org.eclipse.jetty:jetty-server | >=9.4.0<=9.4.56 | 9.4.57.v20241219 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13009 has a medium severity rating due to the potential for data corruption and inadvertent sharing between requests.
To fix CVE-2024-13009, update Eclipse Jetty to a version beyond 9.4.56.
Eclipse Jetty versions from 9.4.0 to 9.4.56 are affected by CVE-2024-13009.
CVE-2024-13009 can lead to corrupted data and inadvertent data sharing between requests due to incorrect buffer handling.
Yes, CVE-2024-13009 poses a risk to production systems that rely on the affected versions of Eclipse Jetty.