CVE-2023-36478
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-36478 affects Eclipse Jetty versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52. The vulnerability stems from an integer overflow in `MetaDataBuilder.checkSize`, which is responsible for determining the size limit of HTTP/2 HPACK header values. When a large user-entered size is multiplied by 4, an overflow occurs, and the check for a negative size is bypassed. Subsequently, a large buffer is allocated on the server, leading to a potential remote denial of service attack. This issue has been rectified in versions 11.0.16, 10.0.16, and 9.4.53, and no workarounds are currently available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.