Improper Resource Shutdown or Release
CVE-2024-13009
Summary
In Eclipse Jetty versions 9.4.0.M0 prior to 9.4.57.v20241219, a buffer may be incorrectly released when a gzip error occurs during the inflation of a request body. This can result in data corruption and/or the inadvertent sharing of data between requests.
- LOW
- NETWORK
- LOW
- CHANGED
- NONE
- NONE
- LOW
- NONE
CWE-404 - Improper Resource Shutdown or Release
The program does not release or incorrectly releases a resource before it is made available for re-use.
References
Advisory Timeline
- Published