Resource exhaustion in Jetty - CVE-2024-22201

 

Resource exhaustion in Jetty - CVE-2024-22201

Published: February 26, 2024


Vulnerability identifier: #VU86808
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22201
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 connections. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Jetty
Rational Functional Tester (RFT)
IBM Observability with Instana
IBM Process Mining
WebSphere Remote Server
Oracle Middleware Common Libraries and Tools
Enterprise Manager Base Platform
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications EAGLE Element Management System
Log Analysis
Netcool Operations Insight
IBM Cloud Pak for Security
IBM MaaS360 Mobile Enterprise Gateway
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct Web Services
IBM MQ
Rational Service Tester
IBM Robotic Process Automation
Integration Bus for z/OS
Cloud Pak for Network Automation
DataStage on Cloud Pak for Data
Oracle Communications ASAP
DevOps
Business Automation Insights
Installation Manager
Packaging Utility
Storage Resource Manager
IBM Secure External Authentication Server
Rational Synergy
Rational Performance Tester
Robotic Process Automation for Cloud Pak
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Development Tools Module
openSUSE Leap
Anolis OS
Jenkins
Jenkins LTS
Oracle Coherence
Dropwizard
watsonx.data
OpenShift Developer Tools and Services
IBM App Connect Enterprise
Rational Change
Oracle Financial Services Compliance Studio
Oracle Retail EFTLink
Oracle AutoVue
Oracle Autovue for Agile Product Lifecycle Management
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
jenkins (Red Hat package)
jenkins-2-plugins (Red Hat package)
jetty-javadoc
jetty-xml
jetty-webapp
jetty-util-ajax
jetty-util
jetty-servlet
jetty-server
jetty-jmx
jetty-jaas
jetty-io
jetty-http
jetty-continuation
jetty-client
jetty-security
jetty
jetty9 (Debian package)
jetty-cdi
jetty-minimal-javadoc
jetty-deploy
jetty-plus
jetty-rewrite
jetty-start
jetty-http-spi
jetty-ant
jetty-quickstart
jetty-jsp
jetty-openid
jetty-annotations
jetty-jndi
jetty-proxy
jetty-servlets
jetty-fcgi
IBM MaaS360 VPN Module
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2024-22201

Install updates from vendor's website.

Jetty - addressed in versions 9.4.54.v20240208, 10.0.20, 11.0.20, 12.0.6
IBM Observability with Instana - update to 1.0.297
IBM Process Mining - update to 1.14.4
Jenkins - update to 2.444
Cloud Pak for Network Automation - update to 2.7.2
Jenkins LTS - update to 2.440.2
Dropwizard - addressed in versions 3.0.7, 4.0.7
DataStage on Cloud Pak for Data - update to 5.2.0
Rational Change - update to 5.3.2.7
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
Log Analysis - update to 1.3.8
Netcool Operations Insight - update to 1.6.12
Installation Manager - update to 1.10.1.1
Packaging Utility - update to 1.10.1.1
IBM Cloud Pak for Security - update to 1.11.2.0
watsonx.data - update to 2.0.2
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.800
IBM MaaS360 VPN Module - update to 3.000.800
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
IBM Secure External Authentication Server - addressed in versions 6.0.3.1, 6.1.0.2
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.24, 6.2.0.23, 6.3.0.7
Rational Synergy - update to 7.2.2.7
IBM MQ - addressed in versions 9.0.0.26, 9.1.0.22, 9.2.0.26, 9.4
jetty-javadoc - update to 9.4.43-2
jetty-xml - update to 9.4.43-2
jetty-webapp - update to 9.4.43-2
jetty-util-ajax - update to 9.4.43-2
jetty-util - update to 9.4.43-2
jetty-servlet - update to 9.4.43-2
jetty-server - update to 9.4.43-2
jetty-jmx - update to 9.4.43-2
jetty-jaas - update to 9.4.43-2
jetty-io - update to 9.4.43-2
jetty-http - update to 9.4.43-2
jetty-continuation - update to 9.4.43-2
jetty-client - update to 9.4.43-2
jetty-security - update to 9.4.43-2
jetty - update to 9.4.43-2
jetty9 (Debian package) - addressed in versions 9.4.50-4+deb11u2, 9.4.50-4+deb12u3
jetty-util - update to 9.4.54-150200.3.25.1
jetty-cdi - update to 9.4.54-150200.3.25.1
jetty-io - update to 9.4.54-150200.3.25.1
jetty-util-ajax - update to 9.4.54-150200.3.25.1
jetty-servlet - update to 9.4.54-150200.3.25.1
jetty-server - update to 9.4.54-150200.3.25.1
jetty-minimal-javadoc - update to 9.4.54-150200.3.25.1
jetty-deploy - update to 9.4.54-150200.3.25.1
jetty-jmx - update to 9.4.54-150200.3.25.1
jetty-jaas - update to 9.4.54-150200.3.25.1
jetty-xml - update to 9.4.54-150200.3.25.1
jetty-plus - update to 9.4.54-150200.3.25.1
jetty-rewrite - update to 9.4.54-150200.3.25.1
jetty-start - update to 9.4.54-150200.3.25.1
jetty-webapp - update to 9.4.54-150200.3.25.1
jetty-http-spi - update to 9.4.54-150200.3.25.1
jetty-continuation - update to 9.4.54-150200.3.25.1
jetty-ant - update to 9.4.54-150200.3.25.1
jetty-quickstart - update to 9.4.54-150200.3.25.1
jetty-jsp - update to 9.4.54-150200.3.25.1
jetty-openid - update to 9.4.54-150200.3.25.1
jetty-annotations - update to 9.4.54-150200.3.25.1
jetty-http - update to 9.4.54-150200.3.25.1
jetty-jndi - update to 9.4.54-150200.3.25.1
jetty-proxy - update to 9.4.54-150200.3.25.1
jetty-servlets - update to 9.4.54-150200.3.25.1
jetty-client - update to 9.4.54-150200.3.25.1
jetty-security - update to 9.4.54-150200.3.25.1
jetty-fcgi - update to 9.4.54-150200.3.25.1
IBM App Connect Enterprise - addressed in versions 11.0.0.26, 12.0.12.0
Rational Service Tester - update to 11.0.2
Rational Performance Tester - update to 11.0.2
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18

External References

Related Security Bulletins