CVE-2020-27218
Last modified
CVE-2020-27218 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.. EPSS estimates a 8.11% chance of exploitation in the next 30 days.
Description
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Eclipse | Jetty | >= 9.4.0, < 9.4.35 | — |
| Eclipse | Jetty | 10.0.0 | Alpha0 |
| Eclipse | Jetty | 11.0.0 | Alpha0 |
| Netapp | Oncommand System Manager | >= 3.0, <= 3.1.3 | — |
| Netapp | Snap Creator Framework | All versions | — |
| Oracle | Blockchain Platform | < 21.1.2 | — |
| Oracle | Communications Converged Application Server - Service Controller | 6.2 | — |
| Oracle | Communications Offline Mediation Controller | 12.0.0.3.0 | — |
| Oracle | Communications Pricing Design Center | 12.0.0.3.0 | — |
| Oracle | Communications Services Gatekeeper | 7.0 | — |
| Oracle | Communications Session Route Manager | >= 8.0.0, <= 8.2.4 | — |
| Oracle | Flexcube Private Banking | 12.0.0 | — |
| Oracle | Flexcube Private Banking | 12.1.0 | — |
| Oracle | Hyperion Infrastructure Technology | 11.1.2.6.0 | — |
| Oracle | Rest Data Services | < 20.4.3.050.1904 | — |
| Oracle | Retail Eftlink | 20.0.0 | — |
| Oracle | Siebel Core - Automation | <= 21.5 | — |
| Apache | Kafka | 2.7.0 | — |
| Apache | Spark | 2.4.8 | — |
| Apache | Spark | 3.0.3 | — |
| Debian | Debian Linux | 10.0 | — |
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=568892Issue Tracking, Vendor Advisory
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-86wm-rrjm-8wh8Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00045.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201218-0003/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=568892Issue Tracking, Vendor Advisory
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-86wm-rrjm-8wh8Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00045.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201218-0003/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27218?
How severe is CVE-2020-27218?
How do I fix CVE-2020-27218?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2721Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…6.5
- CVE-2020-27211Nordic Semiconductor nRF52840 devices through 2020-10-19 hav…5.7
- CVE-2020-27212STMicroelectronics STM32L4 devices through 2020-10-19 have i…7
- CVE-2020-27213An issue was discovered in Ethernut Nut/OS 5.1. The code tha…7.5
- CVE-2020-27216In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.…7
- CVE-2020-27217In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol ad…7.5
- CVE-2020-27219In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP…6.1
- CVE-2020-2722Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…5.4
- CVE-2020-27220The Eclipse Hono AMQP and MQTT protocol adapters do not chec…8.8
- CVE-2020-27221In Eclipse OpenJ9 up to and including version 0.23, there is…9.8
- CVE-2020-27222In Eclipse Californium version 2.3.0 to 2.6.0, the certifica…7.5
- CVE-2020-27223In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclus…5.3
Are you affected by CVE-2020-27218?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
