← back
CVE-2020-27223mediumCWE-407

CVE-2020-27223

35Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.2epss 78%
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
8 products (52 components)
Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 8 · Red Hat OpenShift Container Platform 4 · Red Hat Enterprise Linux 6 · Red Hat Integration Camel Quarkus 1 · and others 3
no_fix_planned: Out of support scope
Fixed
10 products (24 components)
8Base-RHMTC-1.4 · Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Container Platform 4.5 · Red Hat OpenShift Container Platform 4.6 · 7Server-RHMTC-1.4 · and others 5
Not affected
6 products (147 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Container Platform 4.5 · Red Hat OpenShift Container Platform 4.6 · Red Hat Decision Manager 7 · Red Hat Process Automation 7 · and others 1
In short

Eclipse Jetty servers can be made to consume excessive CPU time when processing HTTP requests with multiple Accept headers containing many quality parameters. This allows attackers to cause a denial of service by exhausting server resources.

Technical detail

CWE-407 (Inefficient Algorithmic Complexity) in Jetty versions 9.4.6 through 9.4.36, 10.0.0, and 11.0.0 allows remote attackers to trigger algorithmic complexity exploitation via crafted HTTP requests with multiple Accept headers containing numerous quality (q) parameters, resulting in prolonged CPU consumption and service unavailability.

Summary generated and translated by AI from the official description.
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H