In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: eclipse

Published: 2019-03-27T19:21:37

Updated: 2020-10-20T21:14:54

Reserved: 2018-06-18T00:00:00


Link: CVE-2018-12545

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-03-27T20:29:03.630

Modified: 2023-11-07T02:52:20.420


Link: CVE-2018-12545

JSON object: View

cve-icon Redhat Information

No data.