// For flags

CVE-2018-12545

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.

En Eclipse Jetty, en versiones 9.3.x y 9.4.x, el servidor es vulnerable a una denegación de servicio (DoS) si un cliente remoto envía frames SETTINGs bastante largos que contienen muchas opciones, o muchos frames SETTINGs pequeños. La vulnerabilidad se debe a las asignaciones adicionales de CPU y memoria necesarias para gestionar las opciones cambiadas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-06-18 CVE Reserved
  • 2019-03-27 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
  • CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
20150601
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
20150608
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
20150612
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
maintenance0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
maintenance1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
maintenance2
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.0
Search vendor "Eclipse" for product "Jetty" and version "9.3.0"
rc1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.1
Search vendor "Eclipse" for product "Jetty" and version "9.3.1"
20150714
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.2
Search vendor "Eclipse" for product "Jetty" and version "9.3.2"
20150730
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.3
Search vendor "Eclipse" for product "Jetty" and version "9.3.3"
20150825
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.3
Search vendor "Eclipse" for product "Jetty" and version "9.3.3"
20150827
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.4
Search vendor "Eclipse" for product "Jetty" and version "9.3.4"
20151005
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.4
Search vendor "Eclipse" for product "Jetty" and version "9.3.4"
20151007
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.4
Search vendor "Eclipse" for product "Jetty" and version "9.3.4"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.4
Search vendor "Eclipse" for product "Jetty" and version "9.3.4"
rc1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.5
Search vendor "Eclipse" for product "Jetty" and version "9.3.5"
20151012
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.6
Search vendor "Eclipse" for product "Jetty" and version "9.3.6"
20151106
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.7
Search vendor "Eclipse" for product "Jetty" and version "9.3.7"
20160115
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.7
Search vendor "Eclipse" for product "Jetty" and version "9.3.7"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.7
Search vendor "Eclipse" for product "Jetty" and version "9.3.7"
rc1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.8
Search vendor "Eclipse" for product "Jetty" and version "9.3.8"
20160311
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.8
Search vendor "Eclipse" for product "Jetty" and version "9.3.8"
20160314
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.8
Search vendor "Eclipse" for product "Jetty" and version "9.3.8"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.9
Search vendor "Eclipse" for product "Jetty" and version "9.3.9"
20160517
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.9
Search vendor "Eclipse" for product "Jetty" and version "9.3.9"
maintenance_0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.9
Search vendor "Eclipse" for product "Jetty" and version "9.3.9"
maintenance_1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.10
Search vendor "Eclipse" for product "Jetty" and version "9.3.10"
20160621
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.10
Search vendor "Eclipse" for product "Jetty" and version "9.3.10"
maintenance_0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.11
Search vendor "Eclipse" for product "Jetty" and version "9.3.11"
20160721
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.11
Search vendor "Eclipse" for product "Jetty" and version "9.3.11"
maintenance_0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.12
Search vendor "Eclipse" for product "Jetty" and version "9.3.12"
20160915
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.13
Search vendor "Eclipse" for product "Jetty" and version "9.3.13"
20161014
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.13
Search vendor "Eclipse" for product "Jetty" and version "9.3.13"
maintenance_0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.14
Search vendor "Eclipse" for product "Jetty" and version "9.3.14"
20161028
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.15
Search vendor "Eclipse" for product "Jetty" and version "9.3.15"
20161220
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.16
Search vendor "Eclipse" for product "Jetty" and version "9.3.16"
20170119
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.16
Search vendor "Eclipse" for product "Jetty" and version "9.3.16"
20170120
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.17
Search vendor "Eclipse" for product "Jetty" and version "9.3.17"
20170317
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.17
Search vendor "Eclipse" for product "Jetty" and version "9.3.17"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.18
Search vendor "Eclipse" for product "Jetty" and version "9.3.18"
20170406
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.19
Search vendor "Eclipse" for product "Jetty" and version "9.3.19"
20170502
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.20
Search vendor "Eclipse" for product "Jetty" and version "9.3.20"
20170531
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.21
Search vendor "Eclipse" for product "Jetty" and version "9.3.21"
20170918
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.21
Search vendor "Eclipse" for product "Jetty" and version "9.3.21"
maintenance_0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.21
Search vendor "Eclipse" for product "Jetty" and version "9.3.21"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.22
Search vendor "Eclipse" for product "Jetty" and version "9.3.22"
20171030
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.23
Search vendor "Eclipse" for product "Jetty" and version "9.3.23"
20180228
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.3.24
Search vendor "Eclipse" for product "Jetty" and version "9.3.24"
20180605
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
20161207
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
20161208
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
maintenance_0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
maintenance_1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
rc1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
rc2
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.0
Search vendor "Eclipse" for product "Jetty" and version "9.4.0"
rc3
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.1
Search vendor "Eclipse" for product "Jetty" and version "9.4.1"
20170120
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.1
Search vendor "Eclipse" for product "Jetty" and version "9.4.1"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.2
Search vendor "Eclipse" for product "Jetty" and version "9.4.2"
20170220
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.2
Search vendor "Eclipse" for product "Jetty" and version "9.4.2"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.3
Search vendor "Eclipse" for product "Jetty" and version "9.4.3"
20170317
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.3
Search vendor "Eclipse" for product "Jetty" and version "9.4.3"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.4
Search vendor "Eclipse" for product "Jetty" and version "9.4.4"
20170410
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.4
Search vendor "Eclipse" for product "Jetty" and version "9.4.4"
20170414
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.4
Search vendor "Eclipse" for product "Jetty" and version "9.4.4"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.5
Search vendor "Eclipse" for product "Jetty" and version "9.4.5"
20170502
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.5
Search vendor "Eclipse" for product "Jetty" and version "9.4.5"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.6
Search vendor "Eclipse" for product "Jetty" and version "9.4.6"
20170531
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.6
Search vendor "Eclipse" for product "Jetty" and version "9.4.6"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.7
Search vendor "Eclipse" for product "Jetty" and version "9.4.7"
20170914
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.7
Search vendor "Eclipse" for product "Jetty" and version "9.4.7"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.7
Search vendor "Eclipse" for product "Jetty" and version "9.4.7"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.8
Search vendor "Eclipse" for product "Jetty" and version "9.4.8"
20171121
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.8
Search vendor "Eclipse" for product "Jetty" and version "9.4.8"
20180619
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.9
Search vendor "Eclipse" for product "Jetty" and version "9.4.9"
20180320
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.10
Search vendor "Eclipse" for product "Jetty" and version "9.4.10"
20180503
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.10
Search vendor "Eclipse" for product "Jetty" and version "9.4.10"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.10
Search vendor "Eclipse" for product "Jetty" and version "9.4.10"
rc1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.11
Search vendor "Eclipse" for product "Jetty" and version "9.4.11"
20180605
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.12
Search vendor "Eclipse" for product "Jetty" and version "9.4.12"
rc0
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.12
Search vendor "Eclipse" for product "Jetty" and version "9.4.12"
rc1
Affected
Eclipse
Search vendor "Eclipse"
Jetty
Search vendor "Eclipse" for product "Jetty"
9.4.12
Search vendor "Eclipse" for product "Jetty" and version "9.4.12"
rc2
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
28
Search vendor "Fedoraproject" for product "Fedora" and version "28"
-
Affected