Description
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-2686 Vulnerability (CVE-2020-2686)
PHP Uncontrolled Resource Consumption Vulnerability (CVE-2017-11142)
TYPO3 Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2022-36104)
Oracle Database Server CVE-2024-21058 Vulnerability (CVE-2024-21058)
WordPress 4.5.x Cross-Domain Flash Injection Vulnerability (4.5 - 4.5.12)