CVE-2020-27223: Apache Nifi
Medium severity, CVSS 5.3. EPSS: 78% chance of exploitation in the next 30 days.
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
Affected products
- Apache Nifi: version 1.13.0 only
- Apache Solr: version 8.8.1 only
- Apache Spark: version 3.1.1 only
- Debian Debian Linux: version 10.0 only
- Eclipse Jetty: from 9.4.7, before 9.4.36 (fixed in 9.4.36); version 9.4.6 only; version 9.4.36 only; version 10.0.0 only; version 11.0.0 only
- Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.70.1
- Netapp E-Series Santricity Web Services: affected versions not specified
- Netapp Element Plug-In For vCenter Server: affected versions not specified
- Netapp Hci: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Management Services For Element Software: affected versions not specified
- Netapp Snap Creator Framework: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Netapp Snapmanager: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Oracle Rest Data Services: before 20.4.3.050.1904 (fixed in 20.4.3.050.1904)
Published 2021-02-26. Last modified 2026-06-17.