Improper control of interaction frequency In jetty9
Description
UNSUPPORTED WHEN ASSIGNED GzipHandler causes part of request body to be seen as request body of a separate request In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 9.4.57-0+deb11u1 | ||
debian 12 | 9.4.57-0+deb12u1 | ||
debian 13 | 9.4.57-1 | ||
debian 14 | 9.4.57-1 | ||
maven | 9.4.57.v20241219 | ||
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.