CVE-2020-27223

Aliases:GHSA-m394-8rww-3jr7BIT-nifi-2020-27223BIT-solr-2020-27223BIT-spark-2020-27223
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 26 Feb 2021, 21:55
Last modified:20 Aug 2025, 10:03

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
33.82% HIGH
34% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Feb 2021, 21:55
Published
Vulnerability first disclosed
20 Aug 2025, 10:03
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

CVSS Metrics

  • v3.1MEDIUMScore: 5.2CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 33.82% Percentile: 97%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-407Inefficient Algorithmic Complexity

    An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Systems

  • apachenifi

    1.13.0

  • UnknownSolr

    8.8.1

  • UnknownSpark

    3.1.1

  • debiandebian_linux

    10.0

  • eclipsejetty

    ≥ 9.4.7, < 9.4.36 | 9.4.6:20170531 | 9.4.6:20180619 | 9.4.36 | 9.4.36:20210114 | 10.0.0 | 11.0.0

  • org.eclipse.jettyjetty-server

    ≥ 9.4.6, < 9.4.37 | ≥ 10.0.0, < 10.0.1 | ≥ 11.0.0, < 11.0.1

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.1

  • netappe-series_santricity_web_services

    na

  • netappelement_plug-in_for_vcenter_server

    na

  • netapphci

    na

  • netapphci_management_node

    na

  • netappmanagement_services_for_element_software

    na

  • netappsnap_creator_framework

    na

  • netappsnapcenter

    na

  • netappsnapmanager

    na

  • netappsolidfire

    na

  • oraclerest_data_services

    < 20.4.3.050.1904

  • the eclipse foundationeclipse jetty

    ≥ 9.4.6.v20170531, < unspecified | ≥ unspecified, ≤ 9.4.36.v20210114 | 10.0.0 | 11.0.0

References (130)