Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43778
HistoryOct 12, 2023 - 5:13 a.m.

Denial Of Service (DoS)

2023-10-1205:13:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
31
org.eclipse.jetty
dos attack
hpack header
integer overflow
application crash
metadatabuilder.java

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.005

Percentile

76.5%

org.eclipse.jetty is vulnerable to Denial Of Service (DoS). The vulnerability arises from the library’s failure to appropriately limit the size in HPACK header values. This allows an attacker to repeatedly send maliciously crafted HTTP messages, leading to an integer overflow and ultimately causing an application crash through the checkSize function in MetaDataBuilder.java.

References

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.005

Percentile

76.5%