Improper Resource Shutdown or Release Affecting org.eclipse.jetty:jetty-server package, versions [9.4.0.M0,9.4.57.v20241219)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGECLIPSEJETTY-10079022
  • published9 May 2025
  • disclosed8 May 2025
  • creditMaisie Wang

Introduced: 8 May 2025

NewCVE-2024-13009  (opens in a new tab)
CWE-404  (opens in a new tab)

How to fix?

Upgrade org.eclipse.jetty:jetty-server to version 9.4.57.v20241219 or higher.

Overview

org.eclipse.jetty:jetty-server is a lightweight highly scalable java based web server and servlet engine.

Affected versions of this package are vulnerable to Improper Resource Shutdown or Release due to an error in handling gzip compression in the GzipHandler. An attacker can corrupt data and inadvertently share it between requests by exploiting the improper release of a buffer when a gzip error occurs during the inflation of a request body.

CVSS Base Scores

version 4.0
version 3.1