![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2022-2048 |
Description: | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.705198 1.3.6.1.4.1.25623.1.0.893079 1.3.6.1.4.1.25623.1.0.148713 1.3.6.1.4.1.25623.1.0.148712 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2022-2048 https://github.com/eclipse/jetty.project/security/advisories/GHSA-wgmr-mf83-7x4j Debian Security Information: DSA-5198 (Google Search) https://www.debian.org/security/2022/dsa-5198 https://lists.debian.org/debian-lts-announce/2022/08/msg00011.html http://www.openwall.com/lists/oss-security/2022/09/09/2 |