imPC@ndo IT

Tracker / CVE-2020-27223

CVE-2020-27223

Medium 5.2

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

Affected products and versions

apache nifi
apache solr
apache spark
debian debian_linux
eclipse jetty
eclipse jetty · 9.4.7 → 9.4.36
netapp e-series_santricity_os_controller · 11.0.0 → 11.70.1
netapp e-series_santricity_web_services
netapp element_plug-in_for_vcenter_server
netapp hci
netapp hci_management_node
netapp management_services_for_element_software
netapp snap_creator_framework
netapp snapcenter
netapp snapmanager
netapp solidfire
oracle rest_data_services · … → 20.4.3.050.1904

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References