VDB
BDU%3A2024-10117
BDU%3A2024-10117
PUBLISHED
CVSS 5 MEDIUM
Уязвимость класса HttpURI контейнера сервлетов Eclipse Jetty, позволяющая нарушителю осуществить SSRF-атаку
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», Eclipse Foundation, Google Inc | РЕД ОС (запись в едином реестре российских программ №3751), Jetty, Android Studio |
Timeline
- Nov 22, 2024 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/25 url
- https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh url
- https://github.com/hapifhir/hapi-fhir/issues/6368 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-jetty-cve-2024-13009-cve-2024-8184-cve-2024-6762-cve-2024-6763/?sphrase_id=1075869 url