In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.277.3"
},
{
"introduced": "0"
},
{
"fixed": "2.286"
}
]
}[
{
"events": [
{
"introduced": "7.2.2"
},
{
"fixed": "9.4.39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "8.0.0.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "8.0.0.0"
},
{
"last_affected": "8.2.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "21.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "21.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.9.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.0"
}
]
},
{
"events": [
{
"introduced": "11.0.0"
},
{
"fixed": "11.70.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "9.10"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28165.json"