VDB

DEBIAN-CVE-2024-22201

DEBIAN-CVE-2024-22201 PUBLISHED CVSS 7.5 HIGH

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:14jetty90, 0, 0
Debian:11jetty99.4.39-3+deb11u2, 9.4.44-1, 9.4.44-2
Debian:13jetty90, 0, 0
Debian:12jetty99.4.50-4, 9.4.50-4+deb12u1, 9.4.50-4+deb12u2

Exploit Intelligence

Timeline

  • Feb 26, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›