Lucene search

K
cve[email protected]CVE-2021-28165
HistoryApr 01, 2021 - 3:15 p.m.

CVE-2021-28165

2021-04-0115:15:14
CWE-755
CWE-400
CWE-551
web.nvd.nist.gov
409
17
eclipse jetty
cpu usage
100%
invalid tls frame
cve-2021-28165
nvd

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.802 High

EPSS

Percentile

98.3%

In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.

Affected configurations

NVD
Node
eclipsejettyRange7.2.29.4.39
OR
eclipsejettyRange10.0.010.0.2
OR
eclipsejettyRange11.0.011.0.2
Node
oracleautovue_for_agile_product_lifecycle_managementMatch21.0.2
OR
oraclecommunications_cloud_native_core_policyMatch1.14.0
OR
oraclecommunications_element_managerMatch8.2.2
OR
oraclecommunications_services_gatekeeperMatch7.0
OR
oraclecommunications_session_report_managerRange8.0.0.08.2.4.0
OR
oraclecommunications_session_route_managerRange8.0.0.08.2.4.0
OR
oraclerest_data_servicesRange<21.3
OR
oraclesiebel_core_-_automationRange21.9
Node
jenkinsjenkinsRange<2.277.3lts
OR
jenkinsjenkinsRange<2.286
Node
netappcloud_managerRange<3.9.8
OR
netappe-series_performance_analyzerRange<3.0
OR
netappe-series_santricity_os_controllerRange11.0.011.70.1
OR
netappe-series_santricity_storageRange<1.10vcenter
OR
netappe-series_santricity_web_servicesRange<5.1web_services_proxy
OR
netappontap_toolsRange<9.10vmware_vsphere
OR
netappsantricity_cloud_connectorMatch-
OR
netappsantricity_web_services_proxyRange<5.1
OR
netappsnapcenterRange<4.6
OR
netappstorage_replication_adapter_for_clustered_data_ontapRange<9.10vmware_vsphere
OR
netappvasa_provider_for_clustered_data_ontapRange<9.10

CNA Affected

[
  {
    "product": "Eclipse Jetty",
    "vendor": "The Eclipse Foundation",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "7.2.2",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "9.4.38",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "10.0.0.alpha0",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10.0.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "11.0.0.alpha0",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "11.0.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

References

Social References

More

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.802 High

EPSS

Percentile

98.3%