Insufficient Resource Pool Affecting org.eclipse.jetty.http2:http2-server package, versions [,9.4.47)[10.0.0-alpha0,10.0.10)[11.0.0-alpha0,11.0.10)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (69th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGECLIPSEJETTYHTTP2-2945451
  • published8 Jul 2022
  • disclosed8 Jul 2022
  • creditbjorncs, hakonhall

Introduced: 8 Jul 2022

CVE-2022-2048  (opens in a new tab)
CWE-410  (opens in a new tab)

How to fix?

Upgrade org.eclipse.jetty.http2:http2-server to version 9.4.47, 10.0.10, 11.0.10 or higher.

Overview

Affected versions of this package are vulnerable to Insufficient Resource Pool due to improper handling of an invalid HTTP/2 request processing, when the selector thread is writing a blocking error response. Exploiting this vulnerability might lead the server to be unresponsive.

CVSS Scores

version 3.1