CVE-2022-2048
Vulnerability Summary
Timeline
Description
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 1.05%• Percentile: 78%
Techniques & Countermeasures
- CWE-410•Insufficient Resource Pool
The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.
- CWE-664•Improper Control of a Resource Through its Lifetime
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
Affected Systems
- debian•debian_linux
10.0 | 11.0
- eclipse•jetty
< 9.4.47 | ≥ 10.0.0, < 10.0.9 | ≥ 11.0.0, < 11.0.9
- Unknown•Jenkins
< 2.263 | < 2.361.1
- org.eclipse.jetty.http2•http2-server
< 9.4.47 | ≥ 10.0.0, < 10.0.10 | ≥ 11.0.0, < 11.0.10
- netapp•element_plug-in_for_vcenter_server
na
- netapp•hci_compute_node_firmware
na
- netapp•management_services_for_element_software_and_netapp_hci
na
- netapp•snapcenter
na
- netapp•solidfire_\&_hci_storage_node
na
- the eclipse foundation•eclipse jetty
≥ 9.4.0, < unspecified | ≥ unspecified, ≤ 9.4.46 | ≥ 10.0.0, < unspecified | ≥ unspecified, ≤ 10.0.9 | ≥ 11.0.0, < unspecified | ≥ unspecified, ≤ 11.0.9
References (8)
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-wgmr-mf83-7x4j
- https://www.debian.org/security/2022/dsa-5198
- https://lists.debian.org/debian-lts-announce/2022/08/msg00011.html
- https://security.netapp.com/advisory/ntap-20220901-0006/
- http://www.openwall.com/lists/oss-security/2022/09/09/2
- https://nvd.nist.gov/vuln/detail/CVE-2022-2048
- https://github.com/eclipse/jetty.project
- https://security.netapp.com/advisory/ntap-20220901-0006