CVE-2020-27218
jetty: buffer not correctly recycled in Gzip Request inflation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.
En Eclipse Jetty versión 9.4.0.RC0 hasta 9.4.34.v20201102, 10.0.0.alpha0 hasta 10.0.0.beta2 y 11.0.0.alpha0 hasta 11.0.0.beta2, si la inflación del cuerpo de la petición GZIP está habilitada y solicita de diferentes clientes se multiplexan en una sola conexión, y si un atacante puede enviar una petición con un cuerpo que es recibido por completo pero no consumido por la aplicación, entonces una petición posterior en la misma conexión verá ese cuerpo antepuesto a su cuerpo. El atacante no verá ningún dato, pero puede inyectar datos en el cuerpo de la petición posterior
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-19 CVE Reserved
- 2020-11-28 CVE Published
- 2024-08-04 CVE Updated
- 2024-11-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-226: Sensitive Information in Resource Not Removed Before Reuse
CAPEC
References (119)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com//security-alerts/cpujul2021.html | 2024-02-16 | |
https://www.oracle.com/security-alerts/cpuApr2021.html | 2024-02-16 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2024-02-16 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2024-02-16 |
URL | Date | SRC |
---|---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=568892 | 2024-02-16 | |
https://access.redhat.com/security/cve/CVE-2020-27218 | 2022-03-23 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1902826 | 2022-03-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | >= 9.4.0 < 9.4.35 Search vendor "Eclipse" for product "Jetty" and version " >= 9.4.0 < 9.4.35" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 10.0.0 Search vendor "Eclipse" for product "Jetty" and version "10.0.0" | alpha0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 10.0.0 Search vendor "Eclipse" for product "Jetty" and version "10.0.0" | alpha1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 10.0.0 Search vendor "Eclipse" for product "Jetty" and version "10.0.0" | beta0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 10.0.0 Search vendor "Eclipse" for product "Jetty" and version "10.0.0" | beta1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 10.0.0 Search vendor "Eclipse" for product "Jetty" and version "10.0.0" | beta2 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 11.0.0 Search vendor "Eclipse" for product "Jetty" and version "11.0.0" | alpha0 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 11.0.0 Search vendor "Eclipse" for product "Jetty" and version "11.0.0" | beta1 |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jetty Search vendor "Eclipse" for product "Jetty" | 11.0.0 Search vendor "Eclipse" for product "Jetty" and version "11.0.0" | beta2 |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand System Manager Search vendor "Netapp" for product "Oncommand System Manager" | >= 3.0 <= 3.1.3 Search vendor "Netapp" for product "Oncommand System Manager" and version " >= 3.0 <= 3.1.3" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snap Creator Framework Search vendor "Netapp" for product "Snap Creator Framework" | - | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Blockchain Platform Search vendor "Oracle" for product "Blockchain Platform" | < 21.1.2 Search vendor "Oracle" for product "Blockchain Platform" and version " < 21.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Converged Application Server - Service Controller Search vendor "Oracle" for product "Communications Converged Application Server - Service Controller" | 6.2 Search vendor "Oracle" for product "Communications Converged Application Server - Service Controller" and version "6.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Offline Mediation Controller Search vendor "Oracle" for product "Communications Offline Mediation Controller" | 12.0.0.3.0 Search vendor "Oracle" for product "Communications Offline Mediation Controller" and version "12.0.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Pricing Design Center Search vendor "Oracle" for product "Communications Pricing Design Center" | 12.0.0.3.0 Search vendor "Oracle" for product "Communications Pricing Design Center" and version "12.0.0.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Services Gatekeeper Search vendor "Oracle" for product "Communications Services Gatekeeper" | 7.0 Search vendor "Oracle" for product "Communications Services Gatekeeper" and version "7.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Route Manager Search vendor "Oracle" for product "Communications Session Route Manager" | >= 8.0.0 <= 8.2.4 Search vendor "Oracle" for product "Communications Session Route Manager" and version " >= 8.0.0 <= 8.2.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.0.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Flexcube Private Banking Search vendor "Oracle" for product "Flexcube Private Banking" | 12.1.0 Search vendor "Oracle" for product "Flexcube Private Banking" and version "12.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hyperion Infrastructure Technology Search vendor "Oracle" for product "Hyperion Infrastructure Technology" | 11.1.2.6.0 Search vendor "Oracle" for product "Hyperion Infrastructure Technology" and version "11.1.2.6.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Rest Data Services Search vendor "Oracle" for product "Rest Data Services" | < 20.4.3.050.1904 Search vendor "Oracle" for product "Rest Data Services" and version " < 20.4.3.050.1904" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Eftlink Search vendor "Oracle" for product "Retail Eftlink" | 20.0.0 Search vendor "Oracle" for product "Retail Eftlink" and version "20.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Siebel Core - Automation Search vendor "Oracle" for product "Siebel Core - Automation" | <= 21.5 Search vendor "Oracle" for product "Siebel Core - Automation" and version " <= 21.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Kafka Search vendor "Apache" for product "Kafka" | 2.7.0 Search vendor "Apache" for product "Kafka" and version "2.7.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Spark Search vendor "Apache" for product "Spark" | 2.4.8 Search vendor "Apache" for product "Spark" and version "2.4.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Spark Search vendor "Apache" for product "Spark" | 3.0.3 Search vendor "Apache" for product "Spark" and version "3.0.3" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|