Tracker / CVE-2020-27223
CVE-2020-27223
Medium 5.2
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Affected products and versions
| apache | nifi |
|---|---|
| apache | solr |
| apache | spark |
| debian | debian_linux |
| eclipse | jetty |
| eclipse | jetty · 9.4.7 → 9.4.36 |
| netapp | e-series_santricity_os_controller · 11.0.0 → 11.70.1 |
| netapp | e-series_santricity_web_services |
| netapp | element_plug-in_for_vcenter_server |
| netapp | hci |
| netapp | hci_management_node |
| netapp | management_services_for_element_software |
| netapp | snap_creator_framework |
| netapp | snapcenter |
| netapp | snapmanager |
| netapp | solidfire |
| oracle | rest_data_services · … → 20.4.3.050.1904 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.