CVE-2020-27223: Apache Nifi

Medium severity, CVSS 5.3. EPSS: 78% chance of exploitation in the next 30 days.

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

Affected products

  • Apache Nifi: version 1.13.0 only
  • Apache Solr: version 8.8.1 only
  • Apache Spark: version 3.1.1 only
  • Debian Debian Linux: version 10.0 only
  • Eclipse Jetty: from 9.4.7, before 9.4.36 (fixed in 9.4.36); version 9.4.6 only; version 9.4.36 only; version 10.0.0 only; version 11.0.0 only
  • Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.70.1
  • Netapp E-Series Santricity Web Services: affected versions not specified
  • Netapp Element Plug-In For vCenter Server: affected versions not specified
  • Netapp Hci: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Management Services For Element Software: affected versions not specified
  • Netapp Snap Creator Framework: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Netapp Snapmanager: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Oracle Rest Data Services: before 20.4.3.050.1904 (fixed in 20.4.3.050.1904)

Published 2021-02-26. Last modified 2026-06-17.