5.8

CVE-2020-27218

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EclipseJetty Version >= 9.4.0 < 9.4.35
EclipseJetty Version10.0.0 Updatealpha0
EclipseJetty Version10.0.0 Updatealpha1
EclipseJetty Version10.0.0 Updatebeta0
EclipseJetty Version10.0.0 Updatebeta1
EclipseJetty Version10.0.0 Updatebeta2
EclipseJetty Version11.0.0 Updatealpha0
EclipseJetty Version11.0.0 Updatebeta1
EclipseJetty Version11.0.0 Updatebeta2
NetappOncommand System Manager Version >= 3.0 <= 3.1.3
OracleBlockchain Platform Version < 21.1.2
OracleCommunications Session Route Manager Version >= 8.0.0 <= 8.2.4
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleRest Data Services SwEdition- Version < 20.4.3.050.1904
OracleRetail Eftlink Version20.0.0
OracleSiebel Core - Automation Version <= 21.5
ApacheKafka Version2.7.0
ApacheSpark Version2.4.8
ApacheSpark Version3.0.3
DebianDebian Linux Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.686
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-226 Sensitive Information in Resource Not Removed Before Reuse

The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.