{"id":"GHSA-h2f4-v4c4-6wx4","summary":"Uncontrolled Resource Consumption in org.eclipse.jetty:jetty-server","details":"In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.","aliases":["CVE-2018-12545"],"modified":"2026-03-30T19:48:43.864510Z","published":"2019-03-28T18:33:38Z","database_specific":{"github_reviewed_at":"2020-06-16T21:38:26Z","nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12545"},{"type":"WEB","url":"https://bugs.eclipse.org/bugs/show_bug.cgi?id=538096"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h2f4-v4c4-6wx4"},{"type":"WEB","url":"https://lists.apache.org/thread.html/13f5241048ec0bf966a6ddd306feaf40de5b20e1f09096b9cddeddf2@%3Ccommits.accumulo.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/70744fe4faba8e2fa7e50a7fc794dd03cb28dad8b21e08ee59bb1606@%3Cdevnull.infra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/febc94ffec9275dcda64633e0276a1400cd318e571009e4cda9b7a79@%3Cnotifications.accumulo.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIS4LALKZNLF5X5IGNGRSKERG7FY4QG6"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"}],"affected":[{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.4.0"},{"fixed":"9.4.12.v20180830"}]}],"versions":["9.4.0.v20161208","9.4.0.v20180619","9.4.1.v20170120","9.4.1.v20180619","9.4.10.RC0","9.4.10.RC1","9.4.10.v20180503","9.4.11.v20180605","9.4.12.RC0","9.4.12.RC1","9.4.12.RC2","9.4.2.v20170220","9.4.2.v20180619","9.4.3.v20170317","9.4.3.v20180619","9.4.4.v20170414","9.4.4.v20180619","9.4.5.v20170502","9.4.5.v20180619","9.4.6.v20170531","9.4.6.v20180619","9.4.7.RC0","9.4.7.v20170914","9.4.7.v20180619","9.4.8.v20171121","9.4.8.v20180619","9.4.9.v20180320"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-h2f4-v4c4-6wx4/GHSA-h2f4-v4c4-6wx4.json","last_known_affected_version_range":"\u003c= 9.4.12.RC2"}},{"package":{"name":"org.eclipse.jetty:jetty-server","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jetty/jetty-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.3.0"},{"fixed":"9.3.25.v20180904"}]}],"versions":["9.3.0.v20150612","9.3.1.v20150714","9.3.10.M0","9.3.10.v20160621","9.3.11.M0","9.3.11.v20160721","9.3.12.v20160915","9.3.13.M0","9.3.13.v20161014","9.3.14.v20161028","9.3.15.v20161220","9.3.16.v20170120","9.3.17.RC0","9.3.17.v20170317","9.3.18.v20170406","9.3.19.v20170502","9.3.2.v20150730","9.3.20.v20170531","9.3.21.M0","9.3.21.RC0","9.3.21.v20170918","9.3.22.v20171030","9.3.23.v20180228","9.3.24.v20180605","9.3.3.v20150827","9.3.4.RC0","9.3.4.RC1","9.3.4.v20151007","9.3.5.v20151012","9.3.6.v20151106","9.3.7.RC0","9.3.7.RC1","9.3.7.v20160115","9.3.8.RC0","9.3.8.v20160314","9.3.9.M0","9.3.9.M1","9.3.9.v20160517"],"database_specific":{"last_known_affected_version_range":"\u003c= 9.3.24.v20180605","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/03/GHSA-h2f4-v4c4-6wx4/GHSA-h2f4-v4c4-6wx4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}