CVE-2020-27223

Aliases:GHSA-m394-8rww-3jr7BIT-nifi-2020-27223BIT-solr-2020-27223BIT-spark-2020-27223DEBIAN-CVE-2020-27223
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 26 Feb 2021, 21:55
Last modified:20 Aug 2025, 10:03

Vulnerability Summary

Overall Risk (default)
medium
37/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
77.95% CRITICAL
78% probability +44.13%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Feb 2021, 21:55
Published
Vulnerability first disclosed
20 Aug 2025, 10:03
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

CVSS Metrics

  • v3.1MEDIUMScore: 5.2CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 77.95% Percentile: 100%

Techniques & Countermeasures

  • CWE-407Inefficient Algorithmic Complexity

    An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • apachenifi

    1.13.0

  • apachesolr

    8.8.1

  • apachespark

    3.1.1

  • debianjetty9

    < 9.4.38-1 | < 9.4.38-1 | < 9.4.38-1 | < 9.4.38-1

  • debiandebian_linux

    10.0

  • eclipsejetty

    ≥ 9.4.7, < 9.4.36 | 9.4.6:20170531 | 9.4.6:20180619 | 9.4.36 | 9.4.36:20210114 | 10.0.0 | 11.0.0

  • org.eclipse.jettyjetty-server

    ≥ 9.4.6, < 9.4.37 | ≥ 10.0.0, < 10.0.1 | ≥ 11.0.0, < 11.0.1

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.1

  • netappe-series_santricity_web_services

    na

  • netappelement_plug-in_for_vcenter_server

    na

  • netapphci

    na

  • netapphci_management_node

    na

  • netappmanagement_services_for_element_software

    na

  • netappsnap_creator_framework

    na

  • netappsnapcenter

    na

  • netappsnapmanager

    na

  • netappsolidfire

    na

  • oraclerest_data_services

    < 20.4.3.050.1904

  • the eclipse foundationeclipse jetty

    ≥ 9.4.6.v20170531, < unspecified | ≥ unspecified, ≤ 9.4.36.v20210114 | 10.0.0 | 11.0.0

References (131)