MEDIUM · 4.8

CVE-2020-27218

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients ...

Vulnerability Description

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
EclipseJetty>= 9.4.0, < 9.4.35
NetappOncommand System Manager>= 3.0, <= 3.1.3
NetappSnap Creator Framework-
OracleBlockchain Platform< 21.1.2
OracleCommunications Converged Application Server - Service Controller6.2
OracleCommunications Offline Mediation Controller12.0.0.3.0
OracleCommunications Pricing Design Center12.0.0.3.0
OracleCommunications Services Gatekeeper7.0
OracleCommunications Session Route Manager>= 8.0.0, <= 8.2.4
OracleFlexcube Private Banking12.0.0
OracleHyperion Infrastructure Technology11.1.2.6.0
OracleRest Data Services< 20.4.3.050.1904
OracleRetail Eftlink20.0.0
OracleSiebel Core - Automation<= 21.5
ApacheKafka2.7.0
ApacheSpark2.4.8
DebianDebian Linux10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-27218?

CVE-2020-27218 is a vulnerability with a CVSS score of 4.8 (MEDIUM). In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients ...

How severe is CVE-2020-27218?

CVE-2020-27218 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-27218?

Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Jetty, Netapp Oncommand System Manager, Netapp Snap Creator Framework, Oracle Blockchain Platform, Oracle Communications Converged Application Server - Service Controller.