ZeroHour

CVE-2022-2048

CVSS 3.1
7.5 high
EPSS
2%p83
Published
()
Modified
Description

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.

Vendors
eclipsedebiannetappjenkins
Products
jetty, debian linux, element plug-in for vcenter server, management services for element software and netapp hci, snapcenter, solidfire \& hci storage node, hci compute node, jenkins
Weakness
CWE-410, CWE-664
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.