REDHAT-BUG-2365135: High severity Eclipse Jetty vulnerability
Published May 8, 2025
·Updated
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
Affected Software
1 affected component
Eclipse Jetty>=9.4.0<=9.4.56
Event History
May 8, 2025
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2365135?
REDHAT-BUG-2365135 is considered a moderate severity vulnerability due to potential data corruption and sharing issues.
2
How do I fix REDHAT-BUG-2365135?
To fix REDHAT-BUG-2365135, upgrade to a version of Eclipse Jetty greater than 9.4.56.
3
What versions of Eclipse Jetty are affected by REDHAT-BUG-2365135?
Eclipse Jetty versions from 9.4.0 to 9.4.56 are affected by REDHAT-BUG-2365135.
4
What type of issue does REDHAT-BUG-2365135 cause?
REDHAT-BUG-2365135 can cause corrupted data and inadvertent sharing of request data due to buffer mismanagement.
5
Is there a workaround for REDHAT-BUG-2365135?
There is no documented workaround for REDHAT-BUG-2365135; the recommended solution is to upgrade the software.