Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Package
Affected versions
>= 10.0.0, <= 10.0.17
      >= 11.0.0, <= 11.0.17
      >= 12.0.0, <= 12.0.3
  Patched versions
10.0.18
      11.0.18
      12.0.4
  Description
        Published by the National Vulnerability Database
      Oct 14, 2024 
    
  
        Published to the GitHub Advisory Database
      Oct 14, 2024 
    
  
        Reviewed
      Oct 14, 2024 
    
  
        Last updated
      Nov 8, 2024 
    
  
Impact
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
Patches
Workarounds
The session usage is intrinsic to the design of the PushCacheFilter. The issue can be avoided by:
References
References