跳转到帖子

SUSE: CVE-2024-8184: SUSE Linux Security Advisory

recommended_posts

发布于
  • Members

SUSE: CVE-2024-8184: SUSE Linux Security Advisory

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:C)
Published
10/14/2024
Created
01/01/2025
Added
12/31/2024
Modified
01/30/2025

Description

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack.By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.

Solution(s)

  • suse-upgrade-jetty-annotations
  • suse-upgrade-jetty-ant
  • suse-upgrade-jetty-cdi
  • suse-upgrade-jetty-client
  • suse-upgrade-jetty-continuation
  • suse-upgrade-jetty-deploy
  • suse-upgrade-jetty-fcgi
  • suse-upgrade-jetty-http
  • suse-upgrade-jetty-http-spi
  • suse-upgrade-jetty-io
  • suse-upgrade-jetty-jaas
  • suse-upgrade-jetty-jmx
  • suse-upgrade-jetty-jndi
  • suse-upgrade-jetty-jsp
  • suse-upgrade-jetty-minimal-javadoc
  • suse-upgrade-jetty-openid
  • suse-upgrade-jetty-plus
  • suse-upgrade-jetty-proxy
  • suse-upgrade-jetty-quickstart
  • suse-upgrade-jetty-rewrite
  • suse-upgrade-jetty-security
  • suse-upgrade-jetty-server
  • suse-upgrade-jetty-servlet
  • suse-upgrade-jetty-servlets
  • suse-upgrade-jetty-start
  • suse-upgrade-jetty-util
  • suse-upgrade-jetty-util-ajax
  • suse-upgrade-jetty-webapp
  • suse-upgrade-jetty-xml

References

  • https://attackerkb.com/topics/cve-2024-8184
  • CVE - 2024-8184
  • 查看数 693
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…