CVE-2018-12545: Improper Input Validation
(updated )
In Eclipse Jetty, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs
frames container containing many settings, or many small SETTINGs
frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
References
Detect and mitigate CVE-2018-12545 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →