CVE-2020-27218

Aliases:GHSA-86wm-rrjm-8wh8BIT-kafka-2020-27218BIT-spark-2020-27218
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 28 Nov 2020, 00:00
Last modified:04 Aug 2024, 16:11

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.8 MEDIUM
v2.0 (nvd)
EPSS Score
0.6% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Nov 2020, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 16:11
Last Modified
Vulnerability information updated

Description

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS Metrics

  • v3.1MEDIUMScore: 4.8CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS Trends

Current EPSS score: 0.60% Percentile: 70%

Techniques & Countermeasures

  • CWE-226Sensitive Information in Resource Not Removed Before Reuse

    The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

Affected Systems

  • apachekafka

    2.7.0

  • UnknownSpark

    2.4.8 | 3.0.3

  • debiandebian_linux

    10.0

  • eclipsejetty

    ≥ 9.4.0, < 9.4.35 | 10.0.0:alpha0 | 10.0.0:alpha1 | 10.0.0:beta0 | 10.0.0:beta1 | 10.0.0:beta2 | 11.0.0:alpha0 | 11.0.0:beta1 | 11.0.0:beta2

  • org.eclipse.jettyjetty-server

    ≥ 9.4.0, < 9.4.35.v20201120

  • netapponcommand_system_manager

    ≥ 3.0, ≤ 3.1.3

  • netappsnap_creator_framework

    na

  • oracleblockchain_platform

    < 21.1.2

  • oraclecommunications_converged_application_server_-_service_controller

    6.2

  • oraclecommunications_offline_mediation_controller

    12.0.0.3.0

  • oraclecommunications_pricing_design_center

    12.0.0.3.0

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_route_manager

    ≥ 8.0.0, ≤ 8.2.4

  • oracleflexcube_private_banking

    12.0.0 | 12.1.0

  • oraclehyperion_infrastructure_technology

    11.1.2.6.0

  • oraclerest_data_services

    < 20.4.3.050.1904

  • oracleretail_eftlink

    20.0.0

  • oraclesiebel_core_-_automation

    ≤ 21.5

  • the eclipse foundationeclipse jetty

    9.4.0.RC0 to 9.4.34.v20201102 | 10.0.0.alpha0 to 10.0.0.beta2 | 11.0.0.alpha0 to 11.0.0.beta2

References (229)