First published: Thu Jul 07 2022(Updated: )
A flaw was found in the Jetty-server package. This flaw allows an attacker to send invalid requests, causing a denial of service in the Jetty Server.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Jetty | >=10.0.0<=10.0.9 | |
Eclipse Jetty | >=11.0.0<=11.0.9 | |
IBM Cognos Command Center | <=10.2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2191 is a vulnerability in the Jetty-server package that allows an attacker to send invalid requests and cause a denial of service.
The severity of CVE-2022-2191 is high with a CVSS score of 7.5.
The Jetty-server package version up to and excluding 10.0.10 and 11.0.10 are affected, as well as Eclipse Jetty versions from 10.0.0 to 10.0.9 and 11.0.0 to 11.0.9. IBM Cognos Command Center versions up to and including 10.2.4.1 are also affected.
To fix CVE-2022-2191, update the Jetty-server package to version 10.0.10 or 11.0.10, or update Eclipse Jetty to a version above 10.0.9 or 11.0.9. For IBM Cognos Command Center, update to a version higher than 10.2.4.1.
You can find more information about CVE-2022-2191 at the following references: [GitHub Issue](https://github.com/eclipse/jetty.project/issues/8161#issuecomment-1178728623), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:0189), [Red Hat CVE Page](https://access.redhat.com/security/cve/cve-2022-2191).