Denial of Service in Eclipse Jetty HTTP/2 Server Implementation
CVE-2022-2048
7.5HIGH
What is CVE-2022-2048?
In the Eclipse Jetty HTTP/2 server implementation, there exists a flaw in error handling when processing invalid HTTP/2 requests. This oversight can lead to failure in properly releasing active connections and their associated resources. As a result, this vulnerability may enable an attacker to exhaust server resources, thereby preventing legitimate requests from being processed, which creates a denial of service scenario.
Affected Version(s)
Eclipse Jetty 9.4.0
Eclipse Jetty <= 9.4.46
Eclipse Jetty 10.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved