In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
2021-02-26T22:15:19.317
2025-08-20T10:15:27.843
Modified
CVSSv3.1: 5.2 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | eclipse | jetty | < 9.4.36 | Yes |
Application | eclipse | jetty | 9.4.6 | Yes |
Application | eclipse | jetty | 9.4.6 | Yes |
Application | eclipse | jetty | 9.4.36 | Yes |
Application | eclipse | jetty | 9.4.36 | Yes |
Application | eclipse | jetty | 10.0.0 | Yes |
Application | eclipse | jetty | 11.0.0 | Yes |
Application | apache | nifi | 1.13.0 | Yes |
Application | apache | spark | 3.1.1 | Yes |
Application | netapp | e-series_santricity_os_controller | ≤ 11.70.1 | Yes |
Application | netapp | e-series_santricity_web_services | - | Yes |
Application | netapp | element_plug-in_for_vcenter_server | - | Yes |
Application | netapp | hci | - | Yes |
Application | netapp | hci_management_node | - | Yes |
Application | netapp | management_services_for_element_software | - | Yes |
Application | netapp | snap_creator_framework | - | Yes |
Application | netapp | snapcenter | - | Yes |
Application | netapp | snapmanager | - | Yes |
Application | netapp | snapmanager | - | Yes |
Application | netapp | solidfire | - | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | apache | solr | 8.8.1 | Yes |
Application | oracle | rest_data_services | < 20.4.3.050.1904 | Yes |