Description
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0383 | In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings. |
Github GHSA |
GHSA-h2f4-v4c4-6wx4 | Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-server |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.170Z
Reserved: 2018-06-18T00:00:00.000Z
Link: CVE-2018-12545
No data.
Status : Modified
Published: 2019-03-27T20:29:03.630
Modified: 2024-11-21T03:45:24.620
Link: CVE-2018-12545
OpenCVE Enrichment
No data.
EUVD
Github GHSA