CVE-2020-27223

MEDIUMCVSS 5.3/10EPSS 77.95%

Last modified

CVE-2020-27223 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.. EPSS estimates a 77.95% chance of exploitation in the next 30 days.

Description

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Probability
77.95%

99.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
EclipseJetty>= 9.4.7, < 9.4.36
EclipseJetty9.4.620170531
EclipseJetty9.4.36
EclipseJetty10.0.0
EclipseJetty11.0.0
ApacheNifi1.13.0
ApacheSpark3.1.1
NetappE-Series Santricity Os Controller>= 11.0.0, <= 11.70.1
NetappE-Series Santricity Web ServicesAll versions
NetappElement Plug-In For Vcenter ServerAll versions
NetappHciAll versions
NetappHci Management NodeAll versions
NetappManagement Services For Element SoftwareAll versions
NetappSnap Creator FrameworkAll versions
NetappSnapcenterAll versions
NetappSnapmanagerAll versions
NetappSolidfireAll versions
DebianDebian Linux10.0
ApacheSolr8.8.1
OracleRest Data Services< 20.4.3.050.1904

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-27223?
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
How severe is CVE-2020-27223?
CVE-2020-27223 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 77.95% probability of exploitation in the next 30 days.
How do I fix CVE-2020-27223?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-27223?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST