CVE-2021-28165
jetty: Resource exhaustion when receiving an invalid large TLS frame
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
En Eclipse Jetty versiones 7.2.2 hasta 9.4.38, versiones 10.0.0.alpha0 hasta 10.0.1 y versiones 11.0.0.alpha0 hasta 11.0.1, el uso de CPU puede alcanzar el 100% al recibir una gran trama TLS no vĂ¡lida.
When using SSL/TLS with Jetty, either with HTTP/1.1, HTTP/2, or WebSocket, the server may receive an invalid large (greater than 17408) TLS frame that is incorrectly handled, causing high CPU resources utilization. The highest threat from this vulnerability is to service availability.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-03-12 CVE Reserved
- 2021-04-01 CVE Published
- 2023-11-02 First Exploit
- 2023-12-16 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-551: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (110)
URL | Date | SRC |
---|---|---|
https://github.com/uthrasri/CVE-2021-28165 | 2023-11-02 | |
https://github.com/eclipse/jetty.project/security/advisories/GHSA-26vr-8j45-3r4w | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://www.oracle.com//security-alerts/cpujul2021.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2021/dsa-4949 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2021-28165 | 2022-09-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1945714 | 2022-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 7.2.2 < 9.4.39 Search vendor "Eclipse" for product "Jetty" and version " >= 7.2.2 < 9.4.39" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 10.0.0 < 10.0.2 Search vendor "Eclipse" for product "Jetty" and version " >= 10.0.0 < 10.0.2" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 11.0.0 < 11.0.2 Search vendor "Eclipse" for product "Jetty" and version " >= 11.0.0 < 11.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Autovue For Agile Product Lifecycle Management Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management" | 21.0.2 Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management" and version "21.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Policy Search vendor "Oracle" for product "Communications Cloud Native Core Policy" | 1.14.0 Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Element Manager Search vendor "Oracle" for product "Communications Element Manager" | 8.2.2 Search vendor "Oracle" for product "Communications Element Manager" and version "8.2.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | 7.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version "7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Report Manager Search vendor "Oracle" for product "Communications Session Report Manager" | >= 8.0.0.0 <= 8.2.4.0 Search vendor "Oracle" for product "Communications Session Report Manager" and version " >= 8.0.0.0 <= 8.2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Route Manager Search vendor "Oracle" for product "Communications Session Route Manager" | >= 8.0.0.0 <= 8.2.4.0 Search vendor "Oracle" for product "Communications Session Route Manager" and version " >= 8.0.0.0 <= 8.2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Rest Data Services Search vendor "Oracle" for product "Rest Data Services" | < 21.3 Search vendor "Oracle" for product "Rest Data Services" and version " < 21.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Siebel Core - Automation Search vendor "Oracle" for product "Siebel Core - Automation" | <= 21.9 Search vendor "Oracle" for product "Siebel Core - Automation" and version " <= 21.9" | - |
Affected
| ||||||
Jenkins Search vendor "Jenkins" | Jenkins Search vendor "Jenkins" for product "Jenkins" | < 2.277.3 Search vendor "Jenkins" for product "Jenkins" and version " < 2.277.3" | lts |
Affected
| ||||||
Jenkins Search vendor "Jenkins" | Jenkins Search vendor "Jenkins" for product "Jenkins" | < 2.286 Search vendor "Jenkins" for product "Jenkins" and version " < 2.286" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Cloud Manager Search vendor "Netapp" for product "Cloud Manager" | < 3.9.8 Search vendor "Netapp" for product "Cloud Manager" and version " < 3.9.8" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Performance Analyzer Search vendor "Netapp" for product "E-series Performance Analyzer" | < 3.0 Search vendor "Netapp" for product "E-series Performance Analyzer" and version " < 3.0" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Os Controller Search vendor "Netapp" for product "E-series Santricity Os Controller" | >= 11.0.0 < 11.70.1 Search vendor "Netapp" for product "E-series Santricity Os Controller" and version " >= 11.0.0 < 11.70.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Storage Search vendor "Netapp" for product "E-series Santricity Storage" | < 1.10 Search vendor "Netapp" for product "E-series Santricity Storage" and version " < 1.10" | vcenter |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Web Services Search vendor "Netapp" for product "E-series Santricity Web Services" | < 5.1 Search vendor "Netapp" for product "E-series Santricity Web Services" and version " < 5.1" | web_services_proxy |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Tools Search vendor "Netapp" for product "Ontap Tools" | < 9.10 Search vendor "Netapp" for product "Ontap Tools" and version " < 9.10" | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Santricity Cloud Connector Search vendor "Netapp" for product "Santricity Cloud Connector" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Santricity Web Services Proxy Search vendor "Netapp" for product "Santricity Web Services Proxy" | < 5.1 Search vendor "Netapp" for product "Santricity Web Services Proxy" and version " < 5.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapcenter Search vendor "Netapp" for product "Snapcenter" | < 4.6 Search vendor "Netapp" for product "Snapcenter" and version " < 4.6" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Storage Replication Adapter For Clustered Data Ontap Search vendor "Netapp" for product "Storage Replication Adapter For Clustered Data Ontap" | < 9.10 Search vendor "Netapp" for product "Storage Replication Adapter For Clustered Data Ontap" and version " < 9.10" | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Vasa Provider For Clustered Data Ontap Search vendor "Netapp" for product "Vasa Provider For Clustered Data Ontap" | < 9.10 Search vendor "Netapp" for product "Vasa Provider For Clustered Data Ontap" and version " < 9.10" | - |
Affected
|