← Back

CVE-2020-27216

nvd nist
Published: Oct 23, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.

Affected (32)

Show all products
1 product
Jetty
5 products
Snap Creator Framework
Snapcenter
Vasa Provider
Virtual Storage Console
Storage Replication Adapter
10 products
1 product
Beam
1 product
Debian Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
From 1.0 to 9.3.29
From 9.4.0 to 9.4.32
Version 10.0.0 alpha1
Version 10.0.0 beta0
Version 10.0.0 beta1
Version 10.0.0 beta2
Version 11.0.0 alpha1
Version 11.0.0 beta1
Version 11.0.0 beta2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
From 7.2
From 7.2
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 7.2
Running on/withPlatform Versions
Vmware
Vsphere
All versions
Configuration D
11 vulnerable
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 2.21.0
Version 2.22.0
Version 2.23.0
Version 2.24.0
Version 2.25.0
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0

References (280)

Source: emo@eclipse.org
ExploitPatchVendor Advisory
Source: emo@eclipse.org
Mailing ListThird Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
Third Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: emo@eclipse.org
Not ApplicableThird Party Advisory
Source: emo@eclipse.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.