CVE-2021-28165
high · 7.5In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
7.5
CVSS
53.9%
EPSS (exploit prob.)
99th
EPSS percentile
2021-04-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-400CWE-551CWE-755
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| eclipse | jetty | >= 7.2.2, < 9.4.39 |
| eclipse | jetty | >= 10.0.0, < 10.0.2 |
| eclipse | jetty | >= 11.0.0, < 11.0.2 |
| oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
| oracle | communications_cloud_native_core_policy | 1.14.0 |
| oracle | communications_element_manager | 8.2.2 |
| oracle | communications_services_gatekeeper | 7.0 |
| oracle | communications_session_report_manager | >= 8.0.0.0, <= 8.2.4.0 |
| oracle | communications_session_route_manager | >= 8.0.0.0, <= 8.2.4.0 |
| oracle | rest_data_services | < 21.3 |
| oracle | siebel_core_-_automation | <= 21.9 |
| jenkins | jenkins | < 2.277.3 |
| jenkins | jenkins | < 2.286 |
| netapp | cloud_manager | < 3.9.8 |
| netapp | e-series_performance_analyzer | < 3.0 |
| netapp | e-series_santricity_os_controller | >= 11.0.0, < 11.70.1 |
| netapp | e-series_santricity_storage | < 1.10 |
| netapp | e-series_santricity_web_services | < 5.1 |
| netapp | ontap_tools | < 9.10 |
| netapp | santricity_cloud_connector | all versions |
| netapp | santricity_web_services_proxy | < 5.1 |
| netapp | snapcenter | < 4.6 |
| netapp | storage_replication_adapter_for_clustered_data_ontap | < 9.10 |
| netapp | vasa_provider_for_clustered_data_ontap | < 9.10 |
Check a specific version with /api/v1/cve/match.
References
- http://www.openwall.com/lists/oss-security/2021/04/20/3
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-26vr-8j45-3r4w
- https://lists.apache.org/thread.html/r002258611ed0c35b82b839d284b43db9dcdec120db8afc1c993137dc%40%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r03ca0b69db1e3e5f72fe484b71370d537cd711cbf334e2913332730a%40%3Cissues.spark.apache.org%3E
- https://lists.apache.org/thread.html/r05db8e0ef01e1280cc7543575ae0fa1c2b4d06a8b928916ef65dd2ad%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r06d54a297cb8217c66e5190912a955fb870ba47da164002bf2baffe5%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r077b76cafb61520c14c87c4fc76419ed664002da0ddac5ad851ae7e7%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r0841b06b48324cfc81325de3c05a92e53f997185f9d71ff47734d961%40%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r0a241b0649beef90d422b42a26a2470d336e59e66970eafd54f9c3e2%40%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0a4797ba6ceea8074f47574a4f3cc11493d514c1fab8203ebd212add%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r0bf3aa065abd23960fc8bdc8090d6bc00d5e391cf94ec4e1f4537ae3%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r0cd1a5e3f4ad4770b44f8aa96572fc09d5b35bec149c0cc247579c42%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r0f02034a33076fd7243cf3a8807d2766e373f5cb2e7fd0c9a78f97c4%40%3Cissues.hbase.apache.org%3E
- https://lists.apache.org/thread.html/r111f1ce28b133a8090ca4f809a1bdf18a777426fc058dc3a16c39c66%40%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r17e26cf9a1e3cbc09522d15ece5d7c7a00cdced7641b92a22a783287%40%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r23785214d47673b811ef119ca3a40f729801865ea1e891572d15faa6%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r2afc72af069a7fe89ca2de847f3ab3971cb1d668a9497c999946cd78%40%3Ccommits.spark.apache.org%3E
- https://lists.apache.org/thread.html/r2ea2f0541121f17e470a0184843720046c59d4bde6d42bf5ca6fad81%40%3Cissues.solr.apache.org%3E
- https://lists.apache.org/thread.html/r2f2d9c3b7cc750a6763d6388bcf5db0c7b467bd8be6ac4d6aea4f0cf%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r31f591a0deac927ede8ccc3eac4bb92697ee2361bf01549f9e3440ca%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r33eb3889ca0aa12720355e64fc2f8f1e8c0c28a4d55b3b4b8891becb%40%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r40136c2010fccf4fb2818a965e5d7ecca470e5f525c232ec5b8eb83a%40%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r401b1c592f295b811608010a70792b11c91885b72af9f9410cffbe35%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r411d75dc6bcefadaaea246549dd18e8d391a880ddf28a796f09ce152%40%3Creviews.spark.apache.org%3E
- https://lists.apache.org/thread.html/r47a7542ab61da865fff3db0fe74bfe76c89a37b6e6d2c2a423f8baee%40%3Creviews.spark.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-28165