CVE-2011-4461
Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
- Affected products
- Jetty
- Oracle Sun Storage Common Array Manager
- = 6.9.0
- CVSS 3.0
- 5.3 MEDIUM
- EPSS
- 5.0% (91th percentile)
- Weakness
- CWE-310
- NVD status
- Modified
- Published
- 2011-12-30
CVE-2011-4461 at NVD
1 known exploit for CVE-2011-4461
Proof-of-concept code and exploit modules indexed by Sploitus