Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27218

Опубликовано: 27 нояб. 2020
Источник: redhat
CVSS3: 4.8

Описание

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

Отчет

In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of jetty. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7jettyNot affected
Red Hat Developer Toolsrh-eclipse-jettyAffected
Red Hat Enterprise Linux 6jetty-eclipseNot affected
Red Hat Enterprise Linux 7jettyNot affected
Red Hat Enterprise Linux 8jettyWill not fix
Red Hat JBoss A-MQ 6jettyOut of support scope
Red Hat JBoss Fuse 6jettyOut of support scope
Red Hat JBoss Fuse Service Works 6jettyOut of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hiveWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-226
https://bugzilla.redhat.com/show_bug.cgi?id=1902826jetty: buffer not correctly recycled in Gzip Request inflation

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
nvd
около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
debian
около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 ...

suse-cvrf
около 5 лет назад

Security update for jetty-minimal

suse-cvrf
около 5 лет назад

Security update for jetty-minimal

4.8 Medium

CVSS3