CVE-2018-12545

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
eclipseCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
eclipsejetty
9.3.0:20150601
eclipsejetty
9.3.0:20150608
eclipsejetty
9.3.0:20150612
eclipsejetty
9.3.0:maintenance0
eclipsejetty
9.3.0:maintenance1
eclipsejetty
9.3.0:maintenance2
eclipsejetty
9.3.0:rc0
eclipsejetty
9.3.0:rc1
eclipsejetty
9.3.1:20150714
eclipsejetty
9.3.2:20150730
eclipsejetty
9.3.3:20150825
eclipsejetty
9.3.3:20150827
eclipsejetty
9.3.4:20151005
eclipsejetty
9.3.4:20151007
eclipsejetty
9.3.4:rc0
eclipsejetty
9.3.4:rc1
eclipsejetty
9.3.5:20151012
eclipsejetty
9.3.6:20151106
eclipsejetty
9.3.7:20160115
eclipsejetty
9.3.7:rc0
eclipsejetty
9.3.7:rc1
eclipsejetty
9.3.8:20160311
eclipsejetty
9.3.8:20160314
eclipsejetty
9.3.8:rc0
eclipsejetty
9.3.9:20160517
eclipsejetty
9.3.9:maintenance_0
eclipsejetty
9.3.9:maintenance_1
eclipsejetty
9.3.10:20160621
eclipsejetty
9.3.10:maintenance_0
eclipsejetty
9.3.11:20160721
eclipsejetty
9.3.11:maintenance_0
eclipsejetty
9.3.12:20160915
eclipsejetty
9.3.13:20161014
eclipsejetty
9.3.13:maintenance_0
eclipsejetty
9.3.14:20161028
eclipsejetty
9.3.15:20161220
eclipsejetty
9.3.16:20170119
eclipsejetty
9.3.16:20170120
eclipsejetty
9.3.17:20170317
eclipsejetty
9.3.17:rc0
eclipsejetty
9.3.18:20170406
eclipsejetty
9.3.19:20170502
eclipsejetty
9.3.20:20170531
eclipsejetty
9.3.21:20170918
eclipsejetty
9.3.21:maintenance_0
eclipsejetty
9.3.21:rc0
eclipsejetty
9.3.22:20171030
eclipsejetty
9.3.23:20180228
eclipsejetty
9.3.24:20180605
eclipsejetty
9.4.0:20161207
eclipsejetty
9.4.0:20161208
eclipsejetty
9.4.0:20180619
eclipsejetty
9.4.0:maintenance_0
eclipsejetty
9.4.0:maintenance_1
eclipsejetty
9.4.0:rc0
eclipsejetty
9.4.0:rc1
eclipsejetty
9.4.0:rc2
eclipsejetty
9.4.0:rc3
eclipsejetty
9.4.1:20170120
eclipsejetty
9.4.1:20180619
eclipsejetty
9.4.2:20170220
eclipsejetty
9.4.2:20180619
eclipsejetty
9.4.3:20170317
eclipsejetty
9.4.3:20180619
eclipsejetty
9.4.4:20170410
eclipsejetty
9.4.4:20170414
eclipsejetty
9.4.4:20180619
eclipsejetty
9.4.5:20170502
eclipsejetty
9.4.5:20180619
eclipsejetty
9.4.6:20170531
eclipsejetty
9.4.6:20180619
eclipsejetty
9.4.7:20170914
eclipsejetty
9.4.7:20180619
eclipsejetty
9.4.7:rc0
eclipsejetty
9.4.8:20171121
eclipsejetty
9.4.8:20180619
eclipsejetty
9.4.9:20180320
eclipsejetty
9.4.10:20180503
eclipsejetty
9.4.10:rc0
eclipsejetty
9.4.10:rc1
eclipsejetty
9.4.11:20180605
eclipsejetty
9.4.12:rc0
eclipsejetty
9.4.12:rc1
eclipsejetty
9.4.12:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jetty9
bullseye (security)
9.4.50-4+deb11u2
fixed
bullseye
9.4.50-4+deb11u2
fixed
bookworm
9.4.50-4+deb12u3
fixed
bookworm (security)
9.4.50-4+deb12u3
fixed
sid
9.4.56-1
fixed
trixie
9.4.56-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jetty8
focal
dne
eoan
dne
bionic
dne
xenial
not-affected
trusty
not-affected
jetty9
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
dne
xenial
not-affected
trusty
dne
References