Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-27223


In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.


Published

2021-02-26T22:15:19.317

Last Modified

2025-08-20T10:15:27.843

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.2 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-407
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse jetty < 9.4.36 Yes
Application eclipse jetty 9.4.6 Yes
Application eclipse jetty 9.4.6 Yes
Application eclipse jetty 9.4.36 Yes
Application eclipse jetty 9.4.36 Yes
Application eclipse jetty 10.0.0 Yes
Application eclipse jetty 11.0.0 Yes
Application apache nifi 1.13.0 Yes
Application apache spark 3.1.1 Yes
Application netapp e-series_santricity_os_controller ≤ 11.70.1 Yes
Application netapp e-series_santricity_web_services - Yes
Application netapp element_plug-in_for_vcenter_server - Yes
Application netapp hci - Yes
Application netapp hci_management_node - Yes
Application netapp management_services_for_element_software - Yes
Application netapp snap_creator_framework - Yes
Application netapp snapcenter - Yes
Application netapp snapmanager - Yes
Application netapp snapmanager - Yes
Application netapp solidfire - Yes
Operating System debian debian_linux 10.0 Yes
Application apache solr 8.8.1 Yes
Application oracle rest_data_services < 20.4.3.050.1904 Yes

References