← All CVEs

CVE-2020-27223

medium · 5.2

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

5.2
CVSS
78.0%
EPSS (exploit prob.)
100th
EPSS percentile
2021-02-26
Published

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Weaknesses

CWE-407CWE-400

Affected products

VendorProductAffected versions
eclipsejetty>= 9.4.7, < 9.4.36
eclipsejetty9.4.6
eclipsejetty9.4.6
eclipsejetty9.4.36
eclipsejetty9.4.36
eclipsejetty10.0.0
eclipsejetty11.0.0
apachenifi1.13.0
apachespark3.1.1
netappe-series_santricity_os_controller>= 11.0.0, <= 11.70.1
netappe-series_santricity_web_servicesall versions
netappelement_plug-in_for_vcenter_serverall versions
netapphciall versions
netapphci_management_nodeall versions
netappmanagement_services_for_element_softwareall versions
netappsnap_creator_frameworkall versions
netappsnapcenterall versions
netappsnapmanagerall versions
netappsnapmanagerall versions
netappsolidfireall versions
debiandebian_linux10.0
apachesolr8.8.1
oraclerest_data_services< 20.4.3.050.1904

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-27223