In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0383 | In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings. |
Github GHSA |
GHSA-h2f4-v4c4-6wx4 | Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-server |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.170Z
Reserved: 2018-06-18T00:00:00
Link: CVE-2018-12545
No data.
Status : Modified
Published: 2019-03-27T20:29:03.630
Modified: 2024-11-21T03:45:24.620
Link: CVE-2018-12545
OpenCVE Enrichment
No data.
EUVD
Github GHSA