VDB

DEBIAN-CVE-2020-27223

DEBIAN-CVE-2020-27223 PUBLISHED CVSS 5.300000190734863 MEDIUM

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Debian:14jetty90, 0, 0
Debian:11jetty90, 0, 0
Debian:12jetty90, 0, 0
Debian:13jetty90, 0, 0

Timeline

  • Feb 26, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›