Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-27223

Опубликовано: 26 фев. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.2

Описание

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

9.4.48-1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

not-affected

9.4.48-1
esm-apps/resolute

not-affected

9.4.48-1
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

DNE

Показывать по

4.3 Medium

CVSS2

5.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

CVSS3: 5.2
nvd
больше 5 лет назад

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

CVSS3: 5.2
debian
больше 5 лет назад

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0 ...

suse-cvrf
больше 5 лет назад

Security update for jetty-minimal

CVSS3: 5.3
github
больше 5 лет назад

DOS vulnerability for Quoted Quality CSV headers

4.3 Medium

CVSS2

5.2 Medium

CVSS3