Skip to main content

Improper Resource Shutdown or Release

CVE-2024-13009

Severity High
Score 7.2/10

Summary

In Eclipse Jetty versions 9.4.0.M0 prior to 9.4.57.v20241219, a buffer may be incorrectly released when a gzip error occurs during the inflation of a request body. This can result in data corruption and/or the inadvertent sharing of data between requests.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-404 - Improper Resource Shutdown or Release

The program does not release or incorrectly releases a resource before it is made available for re-use.

Advisory Timeline

  • Published