CVE-2021-28165
HIGHEclipse Jetty 7.2.2-9.4.38, 10.0.0.alpha0-10.0.1, 11.0.0.alpha0-11.0.1 - Denial of Service via Invalid TLS Frame
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-28165. PoCs published by uthrasri.
AI-analyzed exploit summary The repository contains source code files from the Eclipse Jetty server, specifically focusing on connection handling and protocol management. It appears to be a snapshot of the vulnerable codebase for CVE-2021-28165, which involves a security issue in Jetty's connection handling, but lacks explicit exploit code or technical analysis.
Description
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Exploits (1)
The repository contains source code files from the Eclipse Jetty server, specifically focusing on connection handling and protocol management. It appears to be a snapshot of the vulnerable codebase for CVE-2021-28165, which involves a security issue in Jetty's connection handling, but lacks explicit exploit code or technical analysis.
References (107)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H