VDB
BDU%3A2025-08601
BDU%3A2025-08601
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость контейнера сервлетов Eclipse Jetty, связанная с некорректной зачисткой или освобождением ресурсов, позволяющая нарушителю обойти внедренные ограничения безопасности
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Fedora Project, Eclipse Foundation, Google Inc, Gradle Inc. | openSUSE Tumbleweed, A-MQ Clients, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, Fedora, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Package Hub, OpenSUSE Leap, SUSE Linux Enterprise Module for Development Tools, Red Hat Satellite, Jetty, Red Hat build of Apache Camel for Spring Boot, Streams for Apache Kafka, Android Studio, Gradle |
Timeline
- Jul 17, 2025 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/48 url
- https://security-tracker.debian.org/tracker/CVE-2024-13009 advisory
- https://www.suse.com/security/cve/CVE-2024-13009.html advisory
- http://repo.red-soft.ru/redos/8.0/x86_64/updates/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2024-13009 advisory
- https://github.com/jetty/jetty.project/security/advisories/GHSA-q4rv-gq96-w7c5_x0001_ url
- https://access.redhat.com/security/cve/CVE-2024-13009 url