cbcvebase.
CVE-2020-27223
published 2021-02-26

CVE-2020-27223: In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a…

PriorityP348medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
77.95%
99.5th percentile
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachenifi
apachesolr
apachespark
debiandebian_linux
debianjetty9< jetty9 9.4.38-1 (bookworm)jetty9 9.4.38-1 (bookworm)
eclipsejetty
eclipsejetty
eclipsejetty
eclipsejetty
eclipsejetty>= 9.4.7 < 9.4.369.4.36
netappe-series_santricity_os_controller11.0.0 – 11.70.1
oraclerest_data_services< 20.4.3.050.190420.4.3.050.1904
the_eclipse_foundationeclipse_jetty
the_eclipse_foundationeclipse_jetty
the_eclipse_foundationeclipse_jetty>= 9.4.6.v20170531 < unspecifiedunspecified
the_eclipse_foundationeclipse_jettyunspecified – 9.4.36.v20210114

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for sustained high CPU usage on Jetty server processes as an indicator of active exploitation of this DoS vulnerability
  • Exploitation is more viable when any of these Jetty configurations are present: default error page/handler, StatisticsServlet exposed to network traffic, application using getLocale API, or pre-compressed static content in DefaultServlet enabled
  • ·Affected Jetty versions are 9.4.6.v20170531 through 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0; fixed in jetty-9.4.37.v20210219, jetty-9.4.38.v20210224, jetty-10.0.1, and jetty-11.0.1
  • ·Attack does not require authentication (PR:N) and no user interaction is needed; any network-exposed Jetty instance with the prerequisite configurations is at risk
  • ·All requests continue to be handled during exploitation but CPU usage increases significantly; this is not a total denial of service but may cause reduced performance or intermittent resource unavailability

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.