imPC@ndo EN

Tracker / CVE-2020-27218

CVE-2020-27218

Media 4.8

In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

Prodotti e versioni affette

apache kafka
apache spark
debian debian_linux
eclipse jetty
eclipse jetty · 9.4.0 → 9.4.35
netapp oncommand_system_manager · 3.0 → 3.1.3
netapp snap_creator_framework
oracle blockchain_platform · … → 21.1.2
oracle communications_converged_application_server_-_service_controller
oracle communications_offline_mediation_controller
oracle communications_pricing_design_center
oracle communications_services_gatekeeper
oracle communications_session_route_manager · 8.0.0 → 8.2.4
oracle flexcube_private_banking
oracle hyperion_infrastructure_technology
oracle rest_data_services · … → 20.4.3.050.1904
oracle retail_eftlink
oracle siebel_core_-_automation · … → 21.5

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti