CVE-2020-27223
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Published:Feb 26, 2021
Last Modified:Aug 20, 2025
EPS:Feb 26, 2021
EPSS Score:0.28074
CVSS Score:5.2
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Nifi
Apache
Nifi
Vendor
Apache
Product
Solr
Apache
Solr
Vendor
Apache
Product
Spark
Apache
Spark
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Eclipse
Product
Jetty
Eclipse
Jetty
Vendor
Netapp
Product
E-series Santricity Os Controller
Netapp
E-series Santricity Os Controller
Vendor
Netapp
Product
E-series Santricity Web Services
Netapp
E-series Santricity Web Services
Vendor
Netapp
Product
Element Plug-in For Vcenter Server
Netapp
Element Plug-in For Vcenter Server
Vendor
Netapp
Product
Hci
Netapp
Hci
Vendor
Netapp
Product
Hci Management Node
Netapp
Hci Management Node
Vendor
Netapp
Product
Management Services For Element Software
Netapp
Management Services For Element Software
Vendor
Netapp
Product
Snap Creator Framework
Netapp
Snap Creator Framework
Vendor
Netapp
Product
Snapcenter
Netapp
Snapcenter
Vendor
Netapp
Product
Snapmanager
Netapp
Snapmanager
Vendor
Netapp
Product
Solidfire
Netapp
Solidfire
Vendor
Oracle
Product
Rest Data Services
Oracle
Rest Data Services
Vendor
Redhat
Product
Amq Broker
Redhat
Amq Broker
Vendor
Redhat
Product
Camel Quarkus
Redhat
Camel Quarkus
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Vendor
Redhat
Product
Openshift
Redhat
Openshift
Vendor
Redhat
Product
Rhmt
Redhat
Rhmt
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
