cbcvebase.
CVE-2022-2048
published 2022-07-07

CVE-2022-2048: In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianjetty9< jetty9 9.4.48-1 (bookworm)jetty9 9.4.48-1 (bookworm)
eclipsejetty< 9.4.479.4.47
eclipsejetty>= 10.0.0 < 10.0.910.0.9
eclipsejetty>= 11.0.0 < 11.0.911.0.9
jenkinsjenkins< 2.2632.263
jenkinsjenkins< 2.361.12.361.1
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_weekly
linuxlinux_kernel>= 5.14.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 5.19.175.19.17
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.20.0 < 6.0.36.0.3
linuxlinux_kernel>= 5.8.0 < 5.15.755.15.75
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
the_eclipse_foundationeclipse_jetty>= 10.0.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= 11.0.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jetty>= 9.4.0 < unspecifiedunspecified
the_eclipse_foundationeclipse_jettyunspecified – 9.4.46

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH