CVE-2018-12545
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
En Eclipse Jetty, en versiones 9.3.x y 9.4.x, el servidor es vulnerable a una denegación de servicio (DoS) si un cliente remoto envía frames SETTINGs bastante largos que contienen muchas opciones, o muchos frames SETTINGs pequeños. La vulnerabilidad se debe a las asignaciones adicionales de CPU y memoria necesarias para gestionar las opciones cambiadas.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-06-18 CVE Reserved
- 2019-03-27 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (9)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | 20150601 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | 20150608 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | 20150612 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | maintenance0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | maintenance1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | maintenance2 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.0 Search vendor "Eclipse" for product "Jetty" and version "9.3.0" | rc1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.1 Search vendor "Eclipse" for product "Jetty" and version "9.3.1" | 20150714 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.2 Search vendor "Eclipse" for product "Jetty" and version "9.3.2" | 20150730 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.3 Search vendor "Eclipse" for product "Jetty" and version "9.3.3" | 20150825 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.3 Search vendor "Eclipse" for product "Jetty" and version "9.3.3" | 20150827 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.4 Search vendor "Eclipse" for product "Jetty" and version "9.3.4" | 20151005 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.4 Search vendor "Eclipse" for product "Jetty" and version "9.3.4" | 20151007 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.4 Search vendor "Eclipse" for product "Jetty" and version "9.3.4" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.4 Search vendor "Eclipse" for product "Jetty" and version "9.3.4" | rc1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.5 Search vendor "Eclipse" for product "Jetty" and version "9.3.5" | 20151012 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.6 Search vendor "Eclipse" for product "Jetty" and version "9.3.6" | 20151106 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.7 Search vendor "Eclipse" for product "Jetty" and version "9.3.7" | 20160115 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.7 Search vendor "Eclipse" for product "Jetty" and version "9.3.7" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.7 Search vendor "Eclipse" for product "Jetty" and version "9.3.7" | rc1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.8 Search vendor "Eclipse" for product "Jetty" and version "9.3.8" | 20160311 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.8 Search vendor "Eclipse" for product "Jetty" and version "9.3.8" | 20160314 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.8 Search vendor "Eclipse" for product "Jetty" and version "9.3.8" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.9 Search vendor "Eclipse" for product "Jetty" and version "9.3.9" | 20160517 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.9 Search vendor "Eclipse" for product "Jetty" and version "9.3.9" | maintenance_0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.9 Search vendor "Eclipse" for product "Jetty" and version "9.3.9" | maintenance_1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.10 Search vendor "Eclipse" for product "Jetty" and version "9.3.10" | 20160621 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.10 Search vendor "Eclipse" for product "Jetty" and version "9.3.10" | maintenance_0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.11 Search vendor "Eclipse" for product "Jetty" and version "9.3.11" | 20160721 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.11 Search vendor "Eclipse" for product "Jetty" and version "9.3.11" | maintenance_0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.12 Search vendor "Eclipse" for product "Jetty" and version "9.3.12" | 20160915 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.13 Search vendor "Eclipse" for product "Jetty" and version "9.3.13" | 20161014 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.13 Search vendor "Eclipse" for product "Jetty" and version "9.3.13" | maintenance_0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.14 Search vendor "Eclipse" for product "Jetty" and version "9.3.14" | 20161028 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.15 Search vendor "Eclipse" for product "Jetty" and version "9.3.15" | 20161220 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.16 Search vendor "Eclipse" for product "Jetty" and version "9.3.16" | 20170119 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.16 Search vendor "Eclipse" for product "Jetty" and version "9.3.16" | 20170120 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.17 Search vendor "Eclipse" for product "Jetty" and version "9.3.17" | 20170317 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.17 Search vendor "Eclipse" for product "Jetty" and version "9.3.17" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.18 Search vendor "Eclipse" for product "Jetty" and version "9.3.18" | 20170406 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.19 Search vendor "Eclipse" for product "Jetty" and version "9.3.19" | 20170502 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.20 Search vendor "Eclipse" for product "Jetty" and version "9.3.20" | 20170531 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.21 Search vendor "Eclipse" for product "Jetty" and version "9.3.21" | 20170918 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.21 Search vendor "Eclipse" for product "Jetty" and version "9.3.21" | maintenance_0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.21 Search vendor "Eclipse" for product "Jetty" and version "9.3.21" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.22 Search vendor "Eclipse" for product "Jetty" and version "9.3.22" | 20171030 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.23 Search vendor "Eclipse" for product "Jetty" and version "9.3.23" | 20180228 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.3.24 Search vendor "Eclipse" for product "Jetty" and version "9.3.24" | 20180605 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | 20161207 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | 20161208 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | maintenance_0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | maintenance_1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | rc1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | rc2 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.0 Search vendor "Eclipse" for product "Jetty" and version "9.4.0" | rc3 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.1 Search vendor "Eclipse" for product "Jetty" and version "9.4.1" | 20170120 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.1 Search vendor "Eclipse" for product "Jetty" and version "9.4.1" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.2 Search vendor "Eclipse" for product "Jetty" and version "9.4.2" | 20170220 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.2 Search vendor "Eclipse" for product "Jetty" and version "9.4.2" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.3 Search vendor "Eclipse" for product "Jetty" and version "9.4.3" | 20170317 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.3 Search vendor "Eclipse" for product "Jetty" and version "9.4.3" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.4 Search vendor "Eclipse" for product "Jetty" and version "9.4.4" | 20170410 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.4 Search vendor "Eclipse" for product "Jetty" and version "9.4.4" | 20170414 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.4 Search vendor "Eclipse" for product "Jetty" and version "9.4.4" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.5 Search vendor "Eclipse" for product "Jetty" and version "9.4.5" | 20170502 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.5 Search vendor "Eclipse" for product "Jetty" and version "9.4.5" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.6 Search vendor "Eclipse" for product "Jetty" and version "9.4.6" | 20170531 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.6 Search vendor "Eclipse" for product "Jetty" and version "9.4.6" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.7 Search vendor "Eclipse" for product "Jetty" and version "9.4.7" | 20170914 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.7 Search vendor "Eclipse" for product "Jetty" and version "9.4.7" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.7 Search vendor "Eclipse" for product "Jetty" and version "9.4.7" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.8 Search vendor "Eclipse" for product "Jetty" and version "9.4.8" | 20171121 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.8 Search vendor "Eclipse" for product "Jetty" and version "9.4.8" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.9 Search vendor "Eclipse" for product "Jetty" and version "9.4.9" | 20180320 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.10 Search vendor "Eclipse" for product "Jetty" and version "9.4.10" | 20180503 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.10 Search vendor "Eclipse" for product "Jetty" and version "9.4.10" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.10 Search vendor "Eclipse" for product "Jetty" and version "9.4.10" | rc1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.11 Search vendor "Eclipse" for product "Jetty" and version "9.4.11" | 20180605 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.12 Search vendor "Eclipse" for product "Jetty" and version "9.4.12" | rc0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.12 Search vendor "Eclipse" for product "Jetty" and version "9.4.12" | rc1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.12 Search vendor "Eclipse" for product "Jetty" and version "9.4.12" | rc2 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 28 Search vendor "Fedoraproject" for product "Fedora" and version "28" | - |
Affected
|