{
  "threat_severity" : "Moderate",
  "public_date" : "2021-02-26T00:00:00Z",
  "bugzilla" : {
    "description" : "jetty: request containing multiple Accept headers with a large number of \"quality\" parameters may lead to DoS",
    "id" : "1934116",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1934116"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values." ],
  "statement" : "In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of jetty.\nSince the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix.\nThis may be fixed in the future.\n[1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated",
  "affected_release" : [ {
    "product_name" : "Red Hat AMQ 7.8.2",
    "release_date" : "2021-07-12T00:00:00Z",
    "advisory" : "RHSA-2021:2689",
    "cpe" : "cpe:/a:redhat:amq_broker:7",
    "package" : "jetty"
  }, {
    "product_name" : "Red Hat AMQ 7.9.0",
    "release_date" : "2021-09-30T00:00:00Z",
    "advisory" : "RHSA-2021:3700",
    "cpe" : "cpe:/a:redhat:amq_broker:7"
  }, {
    "product_name" : "Red Hat Fuse 7.10",
    "release_date" : "2021-12-14T00:00:00Z",
    "advisory" : "RHSA-2021:5134",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "jetty"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 1",
    "release_date" : "2021-11-23T00:00:00Z",
    "advisory" : "RHSA-2021:4767",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2.2"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-controller-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-operator-bundle:v1.4.6-5"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-registry-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-ui-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-migration-velero-rhel8:v1.4.6-5"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.4",
    "release_date" : "2021-07-21T00:00:00Z",
    "advisory" : "RHBA-2021:2854",
    "cpe" : "cpe:/a:redhat:rhmt:1.4::el7",
    "package" : "rhmtc/openshift-velero-plugin-rhel8:v1.4.6-4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "release_date" : "2021-06-30T00:00:00Z",
    "advisory" : "RHSA-2021:2517",
    "cpe" : "cpe:/a:redhat:openshift:3.11::el7",
    "package" : "jenkins-0:2.289.1.1624365627-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.5",
    "release_date" : "2021-07-02T00:00:00Z",
    "advisory" : "RHSA-2021:2431",
    "cpe" : "cpe:/a:redhat:openshift:4.5::el7",
    "package" : "jenkins-0:2.277.3.1623846768-1.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.6",
    "release_date" : "2021-06-29T00:00:00Z",
    "advisory" : "RHSA-2021:2499",
    "cpe" : "cpe:/a:redhat:openshift:4.6::el8",
    "package" : "jenkins-0:2.277.3.1623853726-1.el8"
  }, {
    "product_name" : "RHAF Camel-K 1.8",
    "release_date" : "2022-09-09T00:00:00Z",
    "advisory" : "RHSA-2022:6407",
    "cpe" : "cpe:/a:redhat:integration:1",
    "package" : "jetty",
    "impact" : "low"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Decision Manager 7",
    "fix_state" : "Not affected",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jetty-eclipse",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Out of support scope",
    "package_name" : "jetty",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "eclipse:rhel8/jetty",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 1",
    "fix_state" : "Affected",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat JBoss A-MQ 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:jboss_amq:6"
  }, {
    "product_name" : "Red Hat JBoss Fuse 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:jboss_fuse:6"
  }, {
    "product_name" : "Red Hat JBoss Fuse Service Works 6",
    "fix_state" : "Out of support scope",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:jboss_fuse_service_works:6"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-metering-hadoop",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-metering-hive",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-metering-presto",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Not affected",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Not affected",
    "package_name" : "jetty",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-27223\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-27223\nhttps://github.com/eclipse/jetty.project/security/advisories/GHSA-m394-8rww-3jr7" ],
  "name" : "CVE-2020-27223",
  "csaw" : false
}