Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-27223

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.337
EPSS Ranking 96.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
References
Products affected by CVE-2020-27223


Contact Us

Shodan ® - All rights reserved