CVE-2018-12545

jetty: Uncontrolled Resource Consumption (CVE-2018-12545)

Description

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
91.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
5.1 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-03-27 19:21 UTC
CWE-400

Weakness classes (CWE)

  • CWE-400Class

    Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

    cwe.mitre.org →

Affected operating systems

  • other

    fedoraproject / fedora28

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • eclipse

    jetty

References & sources

IDCVE-2018-12545