PT-2020-5497 · Eclipse+2 · Eclipse Jetty+2

Published

2020-10-23

·

Updated

2022-03-01

·

CVE-2020-27216

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Jetty versions 1.0 through 9.4.32.v20200930 Eclipse Jetty versions 10.0.0.alpha1 through 10.0.0.beta2 Eclipse Jetty versions 11.0.0.alpha1 through 11.0.0.beta2
Description The issue is related to the creation of temporary files with insecure permissions in the Eclipse Jetty servlet container. On Unix-like systems, the system's temporary directory is shared between all users, allowing a collocated user to observe and potentially race to complete the creation of a temporary subdirectory. If the attacker succeeds, they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. This can lead to a local privilege escalation vulnerability if any code is executed out of this temporary directory.
Recommendations For Eclipse Jetty versions 1.0 through 9.4.32.v20200930, consider updating to a version that fixes the issue. For Eclipse Jetty versions 10.0.0.alpha1 through 10.0.0.beta2, consider updating to a version that fixes the issue. For Eclipse Jetty versions 11.0.0.alpha1 through 11.0.0.beta2, consider updating to a version that fixes the issue. As a temporary workaround, consider restricting access to the temporary directory to minimize the risk of exploitation.

Exploit

Fix

LPE

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1992
BDU:2021-00878
CVE-2020-27216
DLA-2661-1
DSA-4949-1
GHSA-G3WG-6MCF-8JJ6
OESA-2021-1052
RHSA-2020:5168
RHSA-2021:2431
RHSA-2021:2499
RHSA-2021:2517

Affected Products

Alt Linux
Astra Linux
Eclipse Jetty