CVE-2024-8184

unknown
Published 2024-10-14 · Modified 2026-02-04
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk

Description

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-8184.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-8184

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed9.4.57-0+deb12u1
debian debianbullseyefixed9.4.57-0+deb11u1
debian debianforkyfixed9.4.56-1
debian debiansidfixed9.4.56-1
debian debiantrixiefixed9.4.56-1
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.eclipse.jetty:jetty-server>=12.0.0,<12.0.912.0.9
java Mavenorg.eclipse.jetty:jetty-server>=10.0.0,<10.0.2410.0.24
java Mavenorg.eclipse.jetty:jetty-server>=11.0.0,<11.0.2411.0.24
java Mavenorg.eclipse.jetty:jetty-server>=9.3.12,<9.4.569.4.56

References

Verify integrity in audit chain (admin only). AS-IS.