In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HEclipse Jetty
APPEclipse10.0.0 – 10.0.911.0.0 – 11.0.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2019-17638CRITICAL9.4PL ✓same product
Eclipse Jetty: wyciek danych między sesjami przez double-release ByteBuffer
CVE-2017-7657CRITICAL9.8PL ✓same product
Eclipse Jetty: integer overflow w parsowaniu chunk length — obejście autoryzacji
CVE-2017-7658CRITICAL9.8PL ✓same product
Eclipse Jetty — pominięcie autoryzacji przez HTTP Request Smuggling
CVE-2016-4800CRITICAL9.8PL ✓same product
Eclipse Jetty: ominięcie zabezpieczeń przez nieprawidłową normalizację ścieżek URL (Windows)
CVE-2023-44487HIGH7.5⚠ KEVsame product
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can ...