CVE-2018-12545
jetty: Uncontrolled Resource Consumption (CVE-2018-12545)
highEPSS 5.1%
Description
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
Metrics
Severity
high
92.63
no public PoC known
7.5
91.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2019-03-27 19:21 UTC
CWE-400
Weakness classes (CWE)
CWE-400Class
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
cwe.mitre.org →
Affected operating systems
other
fedoraproject / fedora28
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
eclipse
jetty
References & sources
- https://nvd.nist.gov/vuln/detail/CVE-2018-12545advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=538096web
- https://github.com/advisories/GHSA-h2f4-v4c4-6wx4advisory
- https://lists.apache.org/thread.html/13f5241048ec0bf966a6ddd306feaf40de5b20e1f09096b9cddeddf2@%3Ccommits.accumulo.apache.org%3Eweb
- https://lists.apache.org/thread.html/70744fe4faba8e2fa7e50a7fc794dd03cb28dad8b21e08ee59bb1606@%3Cdevnull.infra.apache.org%3Eweb
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3Eweb
- https://lists.apache.org/thread.html/febc94ffec9275dcda64633e0276a1400cd318e571009e4cda9b7a79@%3Cnotifications.accumulo.apache.org%3Eweb
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3Eweb
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIS4LALKZNLF5X5IGNGRSKERG7FY4QG6web
- https://www.oracle.com/security-alerts/cpuoct2020.htmlweb
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlweb
- https://lists.apache.org/thread.html/70744fe4faba8e2fa7e50a7fc794dd03cb28dad8b21e08ee59bb1606%40%3Cdevnull.infra.apache.org%3Emailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/febc94ffec9275dcda64633e0276a1400cd318e571009e4cda9b7a79%40%3Cnotifications.accumulo.apache.org%3Emailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/13f5241048ec0bf966a6ddd306feaf40de5b20e1f09096b9cddeddf2%40%3Ccommits.accumulo.apache.org%3Emailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Emailing-listx_refsource_MLIST
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIS4LALKZNLF5X5IGNGRSKERG7FY4QG6/vendor-advisoryx_refsource_FEDORA
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Emailing-listx_refsource_MLIST
IDCVE-2018-12545