7.5
CVSSv3

CVE-2018-12545

Published: 27/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse jetty 9.3.0

eclipse jetty 9.3.4

eclipse jetty 9.3.7

eclipse jetty 9.3.8

eclipse jetty 9.3.1

eclipse jetty 9.3.2

eclipse jetty 9.3.3

eclipse jetty 9.3.5

eclipse jetty 9.3.6

eclipse jetty 9.3.9

eclipse jetty 9.3.10

eclipse jetty 9.3.11

eclipse jetty 9.3.12

eclipse jetty 9.3.13

eclipse jetty 9.3.14

eclipse jetty 9.3.15

eclipse jetty 9.3.16

eclipse jetty 9.3.17

eclipse jetty 9.3.18

eclipse jetty 9.3.19

eclipse jetty 9.3.20

eclipse jetty 9.3.21

eclipse jetty 9.3.22

eclipse jetty 9.3.23

eclipse jetty 9.3.24

eclipse jetty 9.4.0

eclipse jetty 9.4.1

eclipse jetty 9.4.2

eclipse jetty 9.4.3

eclipse jetty 9.4.4

eclipse jetty 9.4.5

eclipse jetty 9.4.6

eclipse jetty 9.4.7

eclipse jetty 9.4.8

eclipse jetty 9.4.9

eclipse jetty 9.4.10

eclipse jetty 9.4.11

eclipse jetty 9.4.12

fedoraproject fedora 28

Vendor Advisories

Impact: Moderate Public Date: 2019-03-20 CWE: CWE-400 Bugzilla: 1696062: CVE-2018-12545 jetty: large se ...