Versio.io

CVE-2020-27218

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 28-11-2020 02:15
Last modified: - 12-05-2022 04:47
Total changes: - 21

Description

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
High
Attack complexity
Network
Attack vector
Low
Availability
None
Confidentiality
Low
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
4.8
Base score
2.2
2.5
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=eclipse AND product=jetty AND version=11.0.0 AND update=beta1
vendor=eclipse AND product=jetty AND version=11.0.0 AND update=beta2
vendor=eclipse AND product=jetty AND version=10.0.0 AND update=beta1
vendor=eclipse AND product=jetty AND version=10.0.0 AND update=beta2
vendor=eclipse AND product=jetty AND version=10.0.0 AND update=beta0
vendor=eclipse AND product=jetty AND version=10.0.0 AND update=alpha0
vendor=eclipse AND product=jetty AND version=10.0.0 AND update=alpha1
vendor=eclipse AND product=jetty AND version=11.0.0 AND update=alpha0
vendor=eclipse AND product=jetty AND versionStartIncluding=9.4.0 AND versionEndExcluding=9.4.35
OR
vendor=netapp AND product=snap_creator_framework AND version=-
vendor=netapp AND product=oncommand_system_manager AND versionEndIncluding=3.1.3 AND versionStartIncluding=3.0
OR
vendor=oracle AND product=flexcube_private_banking AND version=12.1.0
vendor=oracle AND product=flexcube_private_banking AND version=12.0.0
vendor=oracle AND product=communications_offline_mediation_controller AND version=12.0.0.3.0
vendor=oracle AND product=communications_services_gatekeeper AND version=7.0
vendor=oracle AND product=communications_pricing_design_center AND version=12.0.0.3.0
vendor=oracle AND product=rest_data_services AND software_edition=- AND versionEndExcluding=20.4.3.050.1904
vendor=oracle AND product=communications_converged_application_server_-_service_controller AND version=6.2
vendor=oracle AND product=communications_session_route_manager AND versionEndIncluding=8.2.4 AND versionStartIncluding=8.0.0
vendor=oracle AND product=siebel_core_-_automation AND versionEndIncluding=21.5
vendor=oracle AND product=retail_eftlink AND version=20.0.0
vendor=oracle AND product=blockchain_platform AND versionEndExcluding=21.1.2
vendor=oracle AND product=hyperion_infrastructure_technology AND version=11.1.2.6.0
OR
vendor=apache AND product=kafka AND version=2.7.0
vendor=apache AND product=spark AND version=2.4.8
vendor=apache AND product=spark AND version=3.0.3
 

Reference

 


Keywords

NVD

 

CVE-2020-27218

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.