CVE-2021-28165
jetty: Resource exhaustion when receiving an invalid large TLS frame
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
En Eclipse Jetty versiones 7.2.2 hasta 9.4.38, versiones 10.0.0.alpha0 hasta 10.0.1 y versiones 11.0.0.alpha0 hasta 11.0.1, el uso de CPU puede alcanzar el 100% al recibir una gran trama TLS no válida.
When using SSL/TLS with Jetty, either with HTTP/1.1, HTTP/2, or WebSocket, the server may receive an invalid large (greater than 17408) TLS frame that is incorrectly handled, causing high CPU resources utilization. The highest threat from this vulnerability is to service availability.
Red Hat Advanced Cluster Management for Kubernetes 2.2.4 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs and security issues. Issues addressed include denial of service and integer overflow vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-12 CVE Reserved
- 2021-04-01 CVE Published
- 2023-11-02 First Exploit
- 2024-08-03 CVE Updated
- 2025-04-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-551: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (111)
URL | Date | SRC |
---|---|---|
https://github.com/uthrasri/CVE-2021-28165 | 2023-11-02 | |
https://github.com/hshivhare67/Jetty_v9.4.31_CVE-2021-28165 | 2023-11-16 | |
https://github.com/eclipse/jetty.project/security/advisories/GHSA-26vr-8j45-3r4w | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://www.oracle.com//security-alerts/cpujul2021.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2021/dsa-4949 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2021-28165 | 2022-09-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1945714 | 2022-09-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 7.2.2 < 9.4.39 Search vendor "Eclipse" for product "Jetty" and version " >= 7.2.2 < 9.4.39" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 10.0.0 < 10.0.2 Search vendor "Eclipse" for product "Jetty" and version " >= 10.0.0 < 10.0.2" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 11.0.0 < 11.0.2 Search vendor "Eclipse" for product "Jetty" and version " >= 11.0.0 < 11.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Autovue For Agile Product Lifecycle Management Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management" | 21.0.2 Search vendor "Oracle" for product "Autovue For Agile Product Lifecycle Management" and version "21.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Policy Search vendor "Oracle" for product "Communications Cloud Native Core Policy" | 1.14.0 Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.14.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Element Manager Search vendor "Oracle" for product "Communications Element Manager" | 8.2.2 Search vendor "Oracle" for product "Communications Element Manager" and version "8.2.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | 7.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version "7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Report Manager Search vendor "Oracle" for product "Communications Session Report Manager" | >= 8.0.0.0 <= 8.2.4.0 Search vendor "Oracle" for product "Communications Session Report Manager" and version " >= 8.0.0.0 <= 8.2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Route Manager Search vendor "Oracle" for product "Communications Session Route Manager" | >= 8.0.0.0 <= 8.2.4.0 Search vendor "Oracle" for product "Communications Session Route Manager" and version " >= 8.0.0.0 <= 8.2.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Rest Data Services Search vendor "Oracle" for product "Rest Data Services" | < 21.3 Search vendor "Oracle" for product "Rest Data Services" and version " < 21.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Siebel Core - Automation Search vendor "Oracle" for product "Siebel Core - Automation" | <= 21.9 Search vendor "Oracle" for product "Siebel Core - Automation" and version " <= 21.9" | - |
Affected
| ||||||
Jenkins Search vendor "Jenkins" | Jenkins Search vendor "Jenkins" for product "Jenkins" | < 2.277.3 Search vendor "Jenkins" for product "Jenkins" and version " < 2.277.3" | lts |
Affected
| ||||||
Jenkins Search vendor "Jenkins" | Jenkins Search vendor "Jenkins" for product "Jenkins" | < 2.286 Search vendor "Jenkins" for product "Jenkins" and version " < 2.286" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Cloud Manager Search vendor "Netapp" for product "Cloud Manager" | < 3.9.8 Search vendor "Netapp" for product "Cloud Manager" and version " < 3.9.8" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Performance Analyzer Search vendor "Netapp" for product "E-series Performance Analyzer" | < 3.0 Search vendor "Netapp" for product "E-series Performance Analyzer" and version " < 3.0" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Os Controller Search vendor "Netapp" for product "E-series Santricity Os Controller" | >= 11.0.0 < 11.70.1 Search vendor "Netapp" for product "E-series Santricity Os Controller" and version " >= 11.0.0 < 11.70.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Storage Search vendor "Netapp" for product "E-series Santricity Storage" | < 1.10 Search vendor "Netapp" for product "E-series Santricity Storage" and version " < 1.10" | vcenter |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Web Services Search vendor "Netapp" for product "E-series Santricity Web Services" | < 5.1 Search vendor "Netapp" for product "E-series Santricity Web Services" and version " < 5.1" | web_services_proxy |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Tools Search vendor "Netapp" for product "Ontap Tools" | < 9.10 Search vendor "Netapp" for product "Ontap Tools" and version " < 9.10" | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Santricity Cloud Connector Search vendor "Netapp" for product "Santricity Cloud Connector" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Santricity Web Services Proxy Search vendor "Netapp" for product "Santricity Web Services Proxy" | < 5.1 Search vendor "Netapp" for product "Santricity Web Services Proxy" and version " < 5.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapcenter Search vendor "Netapp" for product "Snapcenter" | < 4.6 Search vendor "Netapp" for product "Snapcenter" and version " < 4.6" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Storage Replication Adapter For Clustered Data Ontap Search vendor "Netapp" for product "Storage Replication Adapter For Clustered Data Ontap" | < 9.10 Search vendor "Netapp" for product "Storage Replication Adapter For Clustered Data Ontap" and version " < 9.10" | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Vasa Provider For Clustered Data Ontap Search vendor "Netapp" for product "Vasa Provider For Clustered Data Ontap" | < 9.10 Search vendor "Netapp" for product "Vasa Provider For Clustered Data Ontap" and version " < 9.10" | - |
Affected
|