CVE-2022-2048

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*
cpe:2.3:a:eclipse:jetty:*:*:*:*:*:*:*:*

Information

Published : 2022-07-07 21:15

Updated : 2022-07-15 15:35


NVD link : CVE-2022-2048

Mitre link : CVE-2022-2048


JSON object : View

Products Affected

eclipse

  • jetty
CWE
CWE-400

Uncontrolled Resource Consumption