ZeroHour

CVE-2021-28165

PoC
CVSS 3.1
7.5 high
EPSS
54%p99
Published
()
Modified
Description

In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.

Vendors
eclipseoraclejenkinsnetapp
Products
jetty, autovue for agile product lifecycle management, communications cloud native core policy, communications element manager, communications services gatekeeper, communications session report manager, communications session route manager, rest data services, siebel core - automation, jenkins, cloud manager, e-series performance analyzer
Weakness
CWE-400, CWE-551, CWE-755
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.