Lucene search

K
osvGoogleOSV:GHSA-QXP4-27VX-XMM3
HistoryMay 14, 2022 - 1:27 a.m.

Improper Input Validation in Jetty

2022-05-1401:27:35
Google
osv.dev
7

0.017 Low

EPSS

Percentile

87.7%

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.