CVE-2024-22201

    Dashboard / Vulnerabilities / CVE-2024-22201

    CVE-2024-22201

    Published: 26 Feb 2024Last Modified: 6 Sept 2026

    Summary: Jetty connection leaking on idle timeout when TCP congested

    Details: Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 390f3200cce7f90f1f3ebc78013c1afea2f93db8

    Affected versions

    jetty-12.0.5
    jetty-12.0.0x

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-22201 | CVE-DB