Race condition in Jetty - CVE-2020-27216

 

Race condition in Jetty - CVE-2020-27216

Published: October 23, 2020 / Updated: December 13, 2020


Vulnerability identifier: #VU48942
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2020-27216
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition. On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.


Affected software

Jetty
Security Directory Integrator
Dell Support Assist Enterprise
IBM Security Verify Directory
Engineering Lifecycle Management - Jazz Foundation
IBM Security Directory Suite
CloudLink
BIG-IP
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Traffix SDC
cri-o (Red Hat package)
jenkins (Red Hat package)
python-requests (Red Hat package)
atomic-openshift (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-web-console (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
openshift-kuryr (Red Hat package)
jenkins-2-plugins (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-clients (Red Hat package)
jetty9 (Debian package)
jetty-client
jetty-util-ajax
jetty-servlet
jetty-javax-websocket-server-impl
jetty-plus
jetty-server
jetty-jstl
jetty-jsp
jetty-http2-hpack
jetty-jmx
jetty-unixsocket
jetty-webapp
jetty-fcgi-client
jetty-javadoc
jetty-servlets
jetty-osgi-boot-jsp
jetty-websocket-common
jetty-http2-http-client-transport
jetty-security
jetty-http2-common
jetty-websocket-api
jetty-jaspi
jetty-alpn-client
jetty-http2-server
jetty-io
jetty-maven-plugin
jetty
jetty-nosql
jetty-ant
jetty-websocket-server
jetty-infinispan
jetty-continuation
jetty-jaas
jetty-jspc-maven-plugin
jetty-fcgi-server
jetty-quickstart
jetty-http2-client
jetty-annotations
jetty-osgi-boot-warurl
jetty-cdi
jetty-spring
jetty-osgi-alpn
jetty-rewrite
jetty-javax-websocket-client-impl
jetty-http
jetty-alpn-server
jetty-util
jetty-proxy
jetty-xml
jetty-osgi-boot
jetty-websocket-client
jetty-project
jetty-deploy
jetty-websocket-servlet
jetty-start
jetty-jndi
jetty-httpservice
jetty-http-spi
Oracle Communications Application Session Controller
IBM Process Mining
IBM Spectrum Protect Storage Agent
IBM Business Automation Workflow
Oracle Communications Services Gatekeeper
Oracle Communications Offline Mediation Controller
BIG-IQ Centralized Management
AMQ Broker
Oracle Communications Element Manager
Oracle FLEXCUBE Core Banking
Oracle Communications Pricing Design Center
Siebel Core - Automation
openEuler
IBM Storage Scale System
Operational Decision Manager
IBM Cognos Analytics

How to mitigate CVE-2020-27216

Install updates from vendor's website.

Jetty - update to 9.4.33.v20201019
Migration Toolkit for Containers - update to 1.4.6
cri-o (Red Hat package) - addressed in versions 1.19.2-6.rhaos4.6.git686e6d9.el7, 1.19.2-6.rhaos4.6.git686e6d9.el8
jenkins (Red Hat package) - addressed in versions 2.277.3.1623846768-1.el7, 2.277.3.1623853726-1.el8, 2.289.1.1624365627-1.el7
python-requests (Red Hat package) - update to 2.19.1-5.el7
Red Hat OpenShift Container Platform - addressed in versions 3.11.462, 4.5.41, 4.6.36
atomic-openshift (Red Hat package) - update to 3.11.462-1.git.0.e7d0362.el7
openshift-ansible (Red Hat package) - addressed in versions 3.11.462-1.git.0.53e69e6.el7, 4.5.0-202106011407.p0.git.83db419.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.462-1.git.99b2acf.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.462-1.git.13de638.el7
atomic-openshift-service-idler (Red Hat package) - addressed in versions 3.11.462-1.git.39cfc66.el7, 4.5.0-202106011407.p0.git.39cfc66.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.462-1.git.f8bf728.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.462-1.git.c8f26da.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.462-1.git.f2f435d.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.462-1.git.656f5d6.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.462-1.git.d435537.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.462-1.git.22be164.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.462-1.git.edebe84.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.462-1.git.609cd20.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.462-1.git.2e6be86.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.462-1.git.99aae51.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.462-1.git.3571208.el7
openshift-kuryr (Red Hat package) - addressed in versions 3.11.462-1.git.c33a657.el7, 4.5.0-202106011407.p0.git.75cc301.el8, 4.6.0-202106181055.p0.git.7feb5bd.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 3.11.1624366838-1.el7, 4.5.1623326336-1.el7
Dell Support Assist Enterprise - update to 4.00.06.00
openshift (Red Hat package) - addressed in versions 4.5.0-202106011407.p0.git.d8ef5ad.el7, 4.5.0-202106011407.p0.git.d8ef5ad.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202106011407.p0.git.f003424.el8
openshift-clients (Red Hat package) - addressed in versions 4.5.0-202106011407.p0.git.297a4ac.el7, 4.5.0-202106011407.p0.git.297a4ac.el8, 4.6.0-202106160917.p0.git.99556b6.el7, 4.6.0-202106160917.p0.git.99556b6.el8
AMQ Broker - addressed in versions 7.4.6, 7.8
jetty9 (Debian package) - update to 9.4.16-0+deb10u1
IBM Process Mining - update to 1.12.0.4
IBM Storage Scale System - update to 5.1.9.0
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix018, 7.1.0 iFix005
IBM Security Directory Suite - update to 8.0.1.21
CloudLink - update to 8.0-3.10.5.1
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty-client - update to 9.4.15-5
jetty-util-ajax - update to 9.4.15-5
jetty-servlet - update to 9.4.15-5
jetty-javax-websocket-server-impl - update to 9.4.15-5
jetty-plus - update to 9.4.15-5
jetty-server - update to 9.4.15-5
jetty-jstl - update to 9.4.15-5
jetty-jsp - update to 9.4.15-5
jetty-http2-hpack - update to 9.4.15-5
jetty-jmx - update to 9.4.15-5
jetty-unixsocket - update to 9.4.15-5
jetty-webapp - update to 9.4.15-5
jetty-fcgi-client - update to 9.4.15-5
jetty-javadoc - update to 9.4.15-5
jetty-servlets - update to 9.4.15-5
jetty-osgi-boot-jsp - update to 9.4.15-5
jetty-websocket-common - update to 9.4.15-5
jetty-http2-http-client-transport - update to 9.4.15-5
jetty-security - update to 9.4.15-5
jetty-http2-common - update to 9.4.15-5
jetty-websocket-api - update to 9.4.15-5
jetty-jaspi - update to 9.4.15-5
jetty-alpn-client - update to 9.4.15-5
jetty-http2-server - update to 9.4.15-5
jetty-io - update to 9.4.15-5
jetty-maven-plugin - update to 9.4.15-5
jetty - update to 9.4.15-5
jetty-nosql - update to 9.4.15-5
jetty-ant - update to 9.4.15-5
jetty-websocket-server - update to 9.4.15-5
jetty-infinispan - update to 9.4.15-5
jetty-continuation - update to 9.4.15-5
jetty-jaas - update to 9.4.15-5
jetty-jspc-maven-plugin - update to 9.4.15-5
jetty-fcgi-server - update to 9.4.15-5
jetty-quickstart - update to 9.4.15-5
jetty-http2-client - update to 9.4.15-5
jetty-annotations - update to 9.4.15-5
jetty-osgi-boot-warurl - update to 9.4.15-5
jetty-cdi - update to 9.4.15-5
jetty-spring - update to 9.4.15-5
jetty-osgi-alpn - update to 9.4.15-5
jetty-rewrite - update to 9.4.15-5
jetty-javax-websocket-client-impl - update to 9.4.15-5
jetty-http - update to 9.4.15-5
jetty-alpn-server - update to 9.4.15-5
jetty-util - update to 9.4.15-5
jetty-proxy - update to 9.4.15-5
jetty-xml - update to 9.4.15-5
jetty-osgi-boot - update to 9.4.15-5
jetty-websocket-client - update to 9.4.15-5
jetty-project - update to 9.4.15-5
jetty-deploy - update to 9.4.15-5
jetty-websocket-servlet - update to 9.4.15-5
jetty-start - update to 9.4.15-5
jetty-jndi - update to 9.4.15-5
jetty-httpservice - update to 9.4.15-5
jetty-http-spi - update to 9.4.15-5
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005

External References

Related Security Bulletins