PT-2020-5497 · Eclipse+2 · Eclipse Jetty+2
Published
2020-10-23
·
Updated
2022-03-01
·
CVE-2020-27216
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Jetty versions 1.0 through 9.4.32.v20200930
Eclipse Jetty versions 10.0.0.alpha1 through 10.0.0.beta2
Eclipse Jetty versions 11.0.0.alpha1 through 11.0.0.beta2
Description
The issue is related to the creation of temporary files with insecure permissions in the Eclipse Jetty servlet container. On Unix-like systems, the system's temporary directory is shared between all users, allowing a collocated user to observe and potentially race to complete the creation of a temporary subdirectory. If the attacker succeeds, they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. This can lead to a local privilege escalation vulnerability if any code is executed out of this temporary directory.
Recommendations
For Eclipse Jetty versions 1.0 through 9.4.32.v20200930, consider updating to a version that fixes the issue.
For Eclipse Jetty versions 10.0.0.alpha1 through 10.0.0.beta2, consider updating to a version that fixes the issue.
For Eclipse Jetty versions 11.0.0.alpha1 through 11.0.0.beta2, consider updating to a version that fixes the issue.
As a temporary workaround, consider restricting access to the temporary directory to minimize the risk of exploitation.
Exploit
Fix
LPE
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Eclipse Jetty