The vendor explicitly states that these products are not affected by this CVE.
- jetty-annotations as a component of Red Hat Enterprise Linux 7
- jetty-ant as a component of Red Hat Enterprise Linux 7
- jetty-client as a component of Red Hat Enterprise Linux 7
- jetty-continuation as a component of Red Hat Enterprise Linux 7
- jetty-deploy as a component of Red Hat Enterprise Linux 7
- jetty-http as a component of Red Hat Enterprise Linux 7
- jetty-io as a component of Red Hat Enterprise Linux 7
- jetty-jaas as a component of Red Hat Enterprise Linux 7
- jetty-jaspi as a component of Red Hat Enterprise Linux 7
- jetty-javadoc as a component of Red Hat Enterprise Linux 7
- jetty-jmx as a component of Red Hat Enterprise Linux 7
- jetty-jndi as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted HTTP requests. Specifically, a buffer leak occurs when processing requests that have a body but read zero bytes, such as 100-Continue requests, or during slow network conditions. This can lead to resource exhaustion and make the server unavailable.
- Remediation
- No remediation text is recorded.
