This repository has been archived by the owner on Jun 16, 2023. It is now read-only.
CVE-2011-4461 (Medium) detected in jetty-server-7.6.21.v20160908.jar #13
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2011-4461 - Medium Severity Vulnerability
The core jetty server artifact.
Library home page: http://www.eclipse.org/jetty
Path to dependency file: /build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/7.6.21.v20160908/a56288d7d1728f06fa01d0f5cd8394177ae249e0/jetty-server-7.6.21.v20160908.jar
Dependency Hierarchy:
Found in HEAD commit: 4cb9afca7b4ab356e0863ec7515cb10a779ea02d
Found in base branch: master
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Publish Date: 2011-12-30
URL: CVE-2011-4461
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4461
Release Date: 2011-12-30
Fix Resolution: 8.1.0.RC4
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: