In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
2019-03-27T20:29:03.630
2024-11-21T03:45:24.620
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.0 | Yes |
Application | eclipse | jetty | 9.3.1 | Yes |
Application | eclipse | jetty | 9.3.2 | Yes |
Application | eclipse | jetty | 9.3.3 | Yes |
Application | eclipse | jetty | 9.3.3 | Yes |
Application | eclipse | jetty | 9.3.4 | Yes |
Application | eclipse | jetty | 9.3.4 | Yes |
Application | eclipse | jetty | 9.3.4 | Yes |
Application | eclipse | jetty | 9.3.4 | Yes |
Application | eclipse | jetty | 9.3.5 | Yes |
Application | eclipse | jetty | 9.3.6 | Yes |
Application | eclipse | jetty | 9.3.7 | Yes |
Application | eclipse | jetty | 9.3.7 | Yes |
Application | eclipse | jetty | 9.3.7 | Yes |
Application | eclipse | jetty | 9.3.8 | Yes |
Application | eclipse | jetty | 9.3.8 | Yes |
Application | eclipse | jetty | 9.3.8 | Yes |
Application | eclipse | jetty | 9.3.9 | Yes |
Application | eclipse | jetty | 9.3.9 | Yes |
Application | eclipse | jetty | 9.3.9 | Yes |
Application | eclipse | jetty | 9.3.10 | Yes |
Application | eclipse | jetty | 9.3.10 | Yes |
Application | eclipse | jetty | 9.3.11 | Yes |
Application | eclipse | jetty | 9.3.11 | Yes |
Application | eclipse | jetty | 9.3.12 | Yes |
Application | eclipse | jetty | 9.3.13 | Yes |
Application | eclipse | jetty | 9.3.13 | Yes |
Application | eclipse | jetty | 9.3.14 | Yes |
Application | eclipse | jetty | 9.3.15 | Yes |
Application | eclipse | jetty | 9.3.16 | Yes |
Application | eclipse | jetty | 9.3.16 | Yes |
Application | eclipse | jetty | 9.3.17 | Yes |
Application | eclipse | jetty | 9.3.17 | Yes |
Application | eclipse | jetty | 9.3.18 | Yes |
Application | eclipse | jetty | 9.3.19 | Yes |
Application | eclipse | jetty | 9.3.20 | Yes |
Application | eclipse | jetty | 9.3.21 | Yes |
Application | eclipse | jetty | 9.3.21 | Yes |
Application | eclipse | jetty | 9.3.21 | Yes |
Application | eclipse | jetty | 9.3.22 | Yes |
Application | eclipse | jetty | 9.3.23 | Yes |
Application | eclipse | jetty | 9.3.24 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.0 | Yes |
Application | eclipse | jetty | 9.4.1 | Yes |
Application | eclipse | jetty | 9.4.1 | Yes |
Application | eclipse | jetty | 9.4.2 | Yes |
Application | eclipse | jetty | 9.4.2 | Yes |
Application | eclipse | jetty | 9.4.3 | Yes |
Application | eclipse | jetty | 9.4.3 | Yes |
Application | eclipse | jetty | 9.4.4 | Yes |
Application | eclipse | jetty | 9.4.4 | Yes |
Application | eclipse | jetty | 9.4.4 | Yes |
Application | eclipse | jetty | 9.4.5 | Yes |
Application | eclipse | jetty | 9.4.5 | Yes |
Application | eclipse | jetty | 9.4.6 | Yes |
Application | eclipse | jetty | 9.4.6 | Yes |
Application | eclipse | jetty | 9.4.7 | Yes |
Application | eclipse | jetty | 9.4.7 | Yes |
Application | eclipse | jetty | 9.4.7 | Yes |
Application | eclipse | jetty | 9.4.8 | Yes |
Application | eclipse | jetty | 9.4.8 | Yes |
Application | eclipse | jetty | 9.4.9 | Yes |
Application | eclipse | jetty | 9.4.10 | Yes |
Application | eclipse | jetty | 9.4.10 | Yes |
Application | eclipse | jetty | 9.4.10 | Yes |
Application | eclipse | jetty | 9.4.11 | Yes |
Application | eclipse | jetty | 9.4.12 | Yes |
Application | eclipse | jetty | 9.4.12 | Yes |
Application | eclipse | jetty | 9.4.12 | Yes |
Operating System | fedoraproject | fedora | 28 | Yes |