CVE-2020-27223
jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
En Eclipse Jetty versiones 9.4.6.v20170531 hasta 9.4.36.v20210114 (inclusive), versiones 10.0.0 y 11.0.0, cuando Jetty maneja una petición que contiene múltiples encabezados Accept con una gran cantidad de parámetros “quality” (es decir, q), el servidor puede entrar en un estado de denegación de servicio (DoS) debido al alto uso de CPU procesando esos valores de calidad, resultando en minutos de tiempo de CPU agotados procesando esos valores de calidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-19 CVE Reserved
- 2021-02-26 CVE Published
- 2021-03-19 First Exploit
- 2024-08-04 CVE Updated
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-407: Inefficient Algorithmic Complexity
CAPEC
References (70)
URL | Date | SRC |
---|---|---|
https://github.com/motikan2010/CVE-2020-27223 | 2021-03-19 | |
https://github.com/ttestoo/Jetty-CVE-2020-27223 | 2021-08-18 |
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpuApr2021.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=571128 | 2023-11-07 | |
https://www.debian.org/security/2021/dsa-4949 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2020-27223 | 2022-09-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1934116 | 2022-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 9.4.7 < 9.4.36 Search vendor "Eclipse" for product "Jetty" and version " >= 9.4.7 < 9.4.36" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.6 Search vendor "Eclipse" for product "Jetty" and version "9.4.6" | 20170531 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.6 Search vendor "Eclipse" for product "Jetty" and version "9.4.6" | 20180619 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.36 Search vendor "Eclipse" for product "Jetty" and version "9.4.36" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 9.4.36 Search vendor "Eclipse" for product "Jetty" and version "9.4.36" | 20210114 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 10.0.0 Search vendor "Eclipse" for product "Jetty" and version "10.0.0" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 11.0.0 Search vendor "Eclipse" for product "Jetty" and version "11.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Nifi Search vendor "Apache" for product "Nifi" | 1.13.0 Search vendor "Apache" for product "Nifi" and version "1.13.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Spark Search vendor "Apache" for product "Spark" | 3.1.1 Search vendor "Apache" for product "Spark" and version "3.1.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Os Controller Search vendor "Netapp" for product "E-series Santricity Os Controller" | >= 11.0.0 <= 11.70.1 Search vendor "Netapp" for product "E-series Santricity Os Controller" and version " >= 11.0.0 <= 11.70.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Web Services Search vendor "Netapp" for product "E-series Santricity Web Services" | - | web_services_proxy |
Affected
| ||||||
Netapp Search vendor "Netapp" | Element Plug-in For Vcenter Server Search vendor "Netapp" for product "Element Plug-in For Vcenter Server" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Search vendor "Netapp" for product "Hci" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Management Node Search vendor "Netapp" for product "Hci Management Node" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Management Services For Element Software Search vendor "Netapp" for product "Management Services For Element Software" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snap Creator Framework Search vendor "Netapp" for product "Snap Creator Framework" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapcenter Search vendor "Netapp" for product "Snapcenter" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapmanager Search vendor "Netapp" for product "Snapmanager" | - | oracle |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapmanager Search vendor "Netapp" for product "Snapmanager" | - | sap |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire Search vendor "Netapp" for product "Solidfire" | - | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Solr Search vendor "Apache" for product "Solr" | 8.8.1 Search vendor "Apache" for product "Solr" and version "8.8.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Rest Data Services Search vendor "Oracle" for product "Rest Data Services" | < 20.4.3.050.1904 Search vendor "Oracle" for product "Rest Data Services" and version " < 20.4.3.050.1904" | - |
Affected
|