Description
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3079-1 | jetty9 security update |
Debian DSA |
DSA-5198-1 | jetty9 security update |
EUVD |
EUVD-2022-6436 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests. |
Github GHSA |
GHSA-wgmr-mf83-7x4j | Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Eclipse
Subscribe
Jetty
Subscribe
Jenkins
Subscribe
Jenkins
Subscribe
Netapp
Subscribe
Element Plug-in For Vcenter Server
Subscribe
Hci Compute Node
Subscribe
Management Services For Element Software And Netapp Hci
Subscribe
Snapcenter
Subscribe
Solidfire \& Hci Storage Node
Subscribe
Redhat
Subscribe
Amq Streams
Subscribe
Jboss Fuse
Subscribe
Ocp Tools
Subscribe
Openshift
Subscribe
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-03T00:24:43.964Z
Reserved: 2022-06-09T00:00:00.000Z
Link: CVE-2022-2048
No data.
Status : Modified
Published: 2022-07-07T21:15:10.150
Modified: 2024-11-21T07:00:13.980
Link: CVE-2022-2048
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA