Back to Database
Status published
Low
CVE-2024-6762
Jetty PushSessionCacheFilter can cause remote DoS attacks
Vulnerability Description
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6762
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Lian Kee
References
- https://github.com/jetty/jetty.project/security/advisories/GHSA-r7m4-f9h5-gr79
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/24
- https://github.com/jetty/jetty.project/pull/9715
- https://github.com/jetty/jetty.project/pull/9716
- https://github.com/jetty/jetty.project/pull/10756
- https://github.com/jetty/jetty.project/pull/10755
More from Eclipse Foundation
View All →CVE-2025-7962
In Jakarta Mail versions prior to 2.0.2 it is possible...
Medium
6
CVE-2025-6705
A vulnerability in the Eclipse Open VSX Registry’s automated publishing...
High
7.6
CVE-2025-55102
A denial-of-service vulnerability exists in the NetX IPv6 component functionality...
High
8.7
CVE-2025-55100
Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()
Low
2.4
CVE-2025-55099
Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()
Low
2.4
Affected Vendor
Eclipse Foundation
View all reports →Affected Software
Jetty
Vulnerable Versions:
10.0.0, 11.0.0, 12.0.0
Timeline
Official Publish:
October 14th, 2024
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L