Логотип exploitDog
bind:CVE-2020-27218
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-27218

Количество 7

Количество 7

ubuntu логотип

CVE-2020-27218

около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2020-27218

около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2020-27218

около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2020-27218

около 5 лет назад

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 ...

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0012-1

около 5 лет назад

Security update for jetty-minimal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3922-1

около 5 лет назад

Security update for jetty-minimal

EPSS: Низкий
github логотип

GHSA-86wm-rrjm-8wh8

около 5 лет назад

Buffer not correctly recycled in Gzip Request inflation

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-27218

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-27218

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-27218

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

CVSS3: 4.8
1%
Низкий
около 5 лет назад
debian логотип
CVE-2020-27218

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 ...

CVSS3: 4.8
1%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0012-1

Security update for jetty-minimal

1%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:3922-1

Security update for jetty-minimal

1%
Низкий
около 5 лет назад
github логотип
GHSA-86wm-rrjm-8wh8

Buffer not correctly recycled in Gzip Request inflation

CVSS3: 4.8
1%
Низкий
около 5 лет назад

Уязвимостей на страницу