REDHAT-BUG-2318564: Medium severity Mortbay Jetty vulnerability
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2318564?
The severity of REDHAT-BUG-2318564 is critical due to its potential to cause remote denial-of-service (DoS) attacks.
How do I fix REDHAT-BUG-2318564?
To fix REDHAT-BUG-2318564, update to the latest version of Eclipse Jetty that includes the patch addressing this vulnerability.
Who is affected by REDHAT-BUG-2318564?
Eclipse Jetty users that rely on ThreadLimitHandler.getRemote() are affected by REDHAT-BUG-2318564.
What type of attack can be executed using REDHAT-BUG-2318564?
REDHAT-BUG-2318564 can be exploited to execute a remote denial-of-service (DoS) attack.
What causes the vulnerability REDHAT-BUG-2318564?
The vulnerability REDHAT-BUG-2318564 is caused by an inability of ThreadLimitHandler.getRemote() to handle crafted requests, leading to OutOfMemory errors.