Denial of Service in Eclipse Jetty HTTP/2 Server Implementation
CVE-2022-2048

7.5HIGH

Key Information:

Vendor
CVE Published:
7 July 2022

What is CVE-2022-2048?

In the Eclipse Jetty HTTP/2 server implementation, there exists a flaw in error handling when processing invalid HTTP/2 requests. This oversight can lead to failure in properly releasing active connections and their associated resources. As a result, this vulnerability may enable an attacker to exhaust server resources, thereby preventing legitimate requests from being processed, which creates a denial of service scenario.

Affected Version(s)

Eclipse Jetty 9.4.0

Eclipse Jetty <= 9.4.46

Eclipse Jetty 10.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-2048 : Denial of Service in Eclipse Jetty HTTP/2 Server Implementation