VDB
DEBIAN-CVE-2020-27223
DEBIAN-CVE-2020-27223
PUBLISHED
CVSS 5.300000190734863 MEDIUM
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | jetty9 | 0, 0, 0 |
| Debian:11 | jetty9 | 0, 0, 0 |
| Debian:12 | jetty9 | 0, 0, 0 |
| Debian:13 | jetty9 | 0, 0, 0 |
Timeline
- Feb 26, 2021 CVE Published
- Apr 28, 2026 CVE Updated