7.5
CVSSv3

CVE-2022-2048

Published: 07/07/2022 Updated: 24/07/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse jetty

debian debian linux 10.0

debian debian linux 11.0

netapp snapcenter -

netapp hci compute node -

netapp solidfire \\& hci storage node -

netapp element plug-in for vcenter server -

netapp management services for element software and netapp hci -

jenkins jenkins

Vendor Advisories

Two security vulnerabilities were discovered in Jetty, a Java servlet engine and webserver CVE-2022-2047 In Eclipse Jetty the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly detects an invalid input as a hostname This can lead to failures in a Proxy scenario CVE-2022-2048 In Eclipse Jet ...
Synopsis Critical: OpenShift Container Platform 4956 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4956 is now available with updates to packages and image ...
Synopsis Moderate: OpenShift Container Platform 4956 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4956 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Platf ...
Synopsis Important: OpenShift Container Platform 4856 packages and security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4856 is now available withupdates to pack ...
Synopsis Important: jenkins and jenkins-2-plugins security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for ...
Synopsis Moderate: Red Hat AMQ Streams 230 release and security update Type/Severity Security Advisory: Moderate Topic Red Hat AMQ Streams 230 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: Red Hat Fuse 7111 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 711 to 7111) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this updat ...
Hitachi Ops Center Analyzer contains the following vulnerabilities: CVE-2022-2047, CVE-2022-2048 Hitachi Ops Center Analyzer viewpoint contains the following vulnerability: CVE-2022-41862 Hitachi Ops Center Viewpoint contains the following vulnerabilities: CVE-2022-41862, CVE-2022-41881, CVE-2022-41915 Affected products and versions ...