Race condition in Jetty - CVE-2020-27216
Published: October 23, 2020 / Updated: December 13, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition. On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.
Affected software
Security Directory Integrator
Dell Support Assist Enterprise
IBM Security Verify Directory
Engineering Lifecycle Management - Jazz Foundation
IBM Security Directory Suite
CloudLink
BIG-IP
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Traffix SDC
cri-o (Red Hat package)
jenkins (Red Hat package)
python-requests (Red Hat package)
atomic-openshift (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-web-console (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
openshift-kuryr (Red Hat package)
jenkins-2-plugins (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-clients (Red Hat package)
jetty9 (Debian package)
jetty-client
jetty-util-ajax
jetty-servlet
jetty-javax-websocket-server-impl
jetty-plus
jetty-server
jetty-jstl
jetty-jsp
jetty-http2-hpack
jetty-jmx
jetty-unixsocket
jetty-webapp
jetty-fcgi-client
jetty-javadoc
jetty-servlets
jetty-osgi-boot-jsp
jetty-websocket-common
jetty-http2-http-client-transport
jetty-security
jetty-http2-common
jetty-websocket-api
jetty-jaspi
jetty-alpn-client
jetty-http2-server
jetty-io
jetty-maven-plugin
jetty
jetty-nosql
jetty-ant
jetty-websocket-server
jetty-infinispan
jetty-continuation
jetty-jaas
jetty-jspc-maven-plugin
jetty-fcgi-server
jetty-quickstart
jetty-http2-client
jetty-annotations
jetty-osgi-boot-warurl
jetty-cdi
jetty-spring
jetty-osgi-alpn
jetty-rewrite
jetty-javax-websocket-client-impl
jetty-http
jetty-alpn-server
jetty-util
jetty-proxy
jetty-xml
jetty-osgi-boot
jetty-websocket-client
jetty-project
jetty-deploy
jetty-websocket-servlet
jetty-start
jetty-jndi
jetty-httpservice
jetty-http-spi
Oracle Communications Application Session Controller
IBM Process Mining
IBM Spectrum Protect Storage Agent
IBM Business Automation Workflow
Oracle Communications Services Gatekeeper
Oracle Communications Offline Mediation Controller
BIG-IQ Centralized Management
AMQ Broker
Oracle Communications Element Manager
Oracle FLEXCUBE Core Banking
Oracle Communications Pricing Design Center
Siebel Core - Automation
openEuler
IBM Storage Scale System
Operational Decision Manager
IBM Cognos Analytics
How to mitigate CVE-2020-27216
Migration Toolkit for Containers - update to 1.4.6
cri-o (Red Hat package) - addressed in versions 1.19.2-6.rhaos4.6.git686e6d9.el7, 1.19.2-6.rhaos4.6.git686e6d9.el8
jenkins (Red Hat package) - addressed in versions 2.277.3.1623846768-1.el7, 2.277.3.1623853726-1.el8, 2.289.1.1624365627-1.el7
python-requests (Red Hat package) - update to 2.19.1-5.el7
Red Hat OpenShift Container Platform - addressed in versions 3.11.462, 4.5.41, 4.6.36
atomic-openshift (Red Hat package) - update to 3.11.462-1.git.0.e7d0362.el7
openshift-ansible (Red Hat package) - addressed in versions 3.11.462-1.git.0.53e69e6.el7, 4.5.0-202106011407.p0.git.83db419.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.462-1.git.99b2acf.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.462-1.git.13de638.el7
atomic-openshift-service-idler (Red Hat package) - addressed in versions 3.11.462-1.git.39cfc66.el7, 4.5.0-202106011407.p0.git.39cfc66.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.462-1.git.f8bf728.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.462-1.git.c8f26da.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.462-1.git.f2f435d.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.462-1.git.656f5d6.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.462-1.git.d435537.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.462-1.git.22be164.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.462-1.git.edebe84.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.462-1.git.609cd20.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.462-1.git.2e6be86.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.462-1.git.99aae51.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.462-1.git.3571208.el7
openshift-kuryr (Red Hat package) - addressed in versions 3.11.462-1.git.c33a657.el7, 4.5.0-202106011407.p0.git.75cc301.el8, 4.6.0-202106181055.p0.git.7feb5bd.el8
jenkins-2-plugins (Red Hat package) - addressed in versions 3.11.1624366838-1.el7, 4.5.1623326336-1.el7
Dell Support Assist Enterprise - update to 4.00.06.00
openshift (Red Hat package) - addressed in versions 4.5.0-202106011407.p0.git.d8ef5ad.el7, 4.5.0-202106011407.p0.git.d8ef5ad.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202106011407.p0.git.f003424.el8
openshift-clients (Red Hat package) - addressed in versions 4.5.0-202106011407.p0.git.297a4ac.el7, 4.5.0-202106011407.p0.git.297a4ac.el8, 4.6.0-202106160917.p0.git.99556b6.el7, 4.6.0-202106160917.p0.git.99556b6.el8
AMQ Broker - addressed in versions 7.4.6, 7.8
jetty9 (Debian package) - update to 9.4.16-0+deb10u1
IBM Process Mining - update to 1.12.0.4
IBM Storage Scale System - update to 5.1.9.0
Engineering Lifecycle Management - Jazz Foundation - addressed in versions 7.0.3 iFix018, 7.1.0 iFix005
IBM Security Directory Suite - update to 8.0.1.21
CloudLink - update to 8.0-3.10.5.1
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty-client - update to 9.4.15-5
jetty-util-ajax - update to 9.4.15-5
jetty-servlet - update to 9.4.15-5
jetty-javax-websocket-server-impl - update to 9.4.15-5
jetty-plus - update to 9.4.15-5
jetty-server - update to 9.4.15-5
jetty-jstl - update to 9.4.15-5
jetty-jsp - update to 9.4.15-5
jetty-http2-hpack - update to 9.4.15-5
jetty-jmx - update to 9.4.15-5
jetty-unixsocket - update to 9.4.15-5
jetty-webapp - update to 9.4.15-5
jetty-fcgi-client - update to 9.4.15-5
jetty-javadoc - update to 9.4.15-5
jetty-servlets - update to 9.4.15-5
jetty-osgi-boot-jsp - update to 9.4.15-5
jetty-websocket-common - update to 9.4.15-5
jetty-http2-http-client-transport - update to 9.4.15-5
jetty-security - update to 9.4.15-5
jetty-http2-common - update to 9.4.15-5
jetty-websocket-api - update to 9.4.15-5
jetty-jaspi - update to 9.4.15-5
jetty-alpn-client - update to 9.4.15-5
jetty-http2-server - update to 9.4.15-5
jetty-io - update to 9.4.15-5
jetty-maven-plugin - update to 9.4.15-5
jetty - update to 9.4.15-5
jetty-nosql - update to 9.4.15-5
jetty-ant - update to 9.4.15-5
jetty-websocket-server - update to 9.4.15-5
jetty-infinispan - update to 9.4.15-5
jetty-continuation - update to 9.4.15-5
jetty-jaas - update to 9.4.15-5
jetty-jspc-maven-plugin - update to 9.4.15-5
jetty-fcgi-server - update to 9.4.15-5
jetty-quickstart - update to 9.4.15-5
jetty-http2-client - update to 9.4.15-5
jetty-annotations - update to 9.4.15-5
jetty-osgi-boot-warurl - update to 9.4.15-5
jetty-cdi - update to 9.4.15-5
jetty-spring - update to 9.4.15-5
jetty-osgi-alpn - update to 9.4.15-5
jetty-rewrite - update to 9.4.15-5
jetty-javax-websocket-client-impl - update to 9.4.15-5
jetty-http - update to 9.4.15-5
jetty-alpn-server - update to 9.4.15-5
jetty-util - update to 9.4.15-5
jetty-proxy - update to 9.4.15-5
jetty-xml - update to 9.4.15-5
jetty-osgi-boot - update to 9.4.15-5
jetty-websocket-client - update to 9.4.15-5
jetty-project - update to 9.4.15-5
jetty-deploy - update to 9.4.15-5
jetty-websocket-servlet - update to 9.4.15-5
jetty-start - update to 9.4.15-5
jetty-jndi - update to 9.4.15-5
jetty-httpservice - update to 9.4.15-5
jetty-http-spi - update to 9.4.15-5
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
External References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=567921
- https://github.com/eclipse/jetty.project/security/advisories/GHSA-g3wg-6mcf-8jj6#advisory-comment-63053
- https://lists.apache.org/thread.html/r07525dc424ed69b3919618599e762f9ac03791490ca9d724f2241442@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r09b345099b4f88d2bed7f195a96145849243fb4e53661aa3bcf4c176@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0df8fe10fc36028cf6d0381ab66510917d0d68bc5ef7042001d03830@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r0e9efe032cc65433251ee6470c66c334d4e7db9101e24cf91a3961f2@%3Ccommits.directory.apache.org%3E
- https://lists.apache.org/thread.html/r0f5e9b93133ef3aaf31484bc3e15cc4b85f8af0fe4de2dacd9379d72@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r100c5c7586a23a19fdb54d8a32e17cd0944bdaa46277b35c397056f6@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r18b6f10d9939419bae9c225d5058c97533cb376c9d6d0a0733ddd48d@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r1d45051310b11c6d6476f20d71b08ea97cb76846cbf61d196bac1c3f@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r1dbb87c9255ecefadd8de514fa1d35c1d493c0527d7672cf40505d04@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r1ed79516bd6d248ea9f0e704dbfd7de740d5a75b71c7be8699fec824@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2d17b2a4803096ba427f3575599ea29b55f5cf9dbc1f12ba044cae1a@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r3a763de620be72b6d74f46ec4bf39c9f35f8a0b39993212c0ac778ec@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r3e05ab0922876e74fea975d70af82b98580f4c14ba643c4f8a9e3a94@%3Cissues.beam.apache.org%3E
- https://lists.apache.org/thread.html/r4f29fb24639ebc5d15fc477656ebc2b3aa00fcfbe197000009c26b40@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r5494fdaf4a0a42a15c49841ba7ae577d466d09239ee1050458da0f29@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r568d354961fa88f206dc345411fb11d245c6dc1a8da3e80187fc6706@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r59e0878013d329dcc481eeafebdb0ee445b1e2852d0c4827b1ddaff2@%3Cissues.beam.apache.org%3E
- https://lists.apache.org/thread.html/r66e99d973fd79ddbcb3fbdb24f4767fe9b911f5b0abb05d7b6f65801@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r769411eb43dd9ef77665700deb7fc491fc3ceb532914260c90b56f2f@%3Cissues.beam.apache.org%3E
- https://lists.apache.org/thread.html/r7da5ae60d7973e8894cfe92f49ecb5b47417eefab4c77cc87514d3cf@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/r874688141495df766e62be095f1dfb0bf4a24ca0340d8e0215c03fab@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r93d5e81e879120d8d87925dbdd4045cb3afa9b066f4370f60b626ce3@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/ra1f19625cc67ac1b459c558f2ea5647d71ce51c6fe4f4cb03baec849@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra55e04d5a73afcb8383f4386e2b26832c6e3972e53827021ab885943@%3Ccommits.shiro.apache.org%3E
- https://lists.apache.org/thread.html/ra5b7313d8cc9411db6790adfba33f2cf0665cb77adb7b02043c95867@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rad255c736fad46135f1339408cb0147d0671e45c376c3be85ceeec1a@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/raf9c581b793c30ff8f55f2415c7bd337eb69775aae607bf9ed1b16fb@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rafb023a7c61180a1027819678eb2068b0b60cd5c2559cb8490e26c81@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rb8c007f87dc57731a7b9a3b05364530422535b7e0bc6a0c5b68d4d55@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rbc5a8d7a0a13bc8152d427a7e9097cdeb139c6cfe111b2f00f26d16b@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rc2e24756d28580eeac811c5c6a12012c9f424b6e5bffb89f98ee3d03@%3Cdev.felix.apache.org%3E
- https://lists.apache.org/thread.html/rc4b972ea10c5a65c6a88a6e233778718ab9af7f484affdd5e5de0cff@%3Ccommits.felix.apache.org%3E
- https://lists.apache.org/thread.html/rd58b60ab2e49ebf21022e59e280feb25899ff785c88f31fe314aa5b9@%3Ccommits.shiro.apache.org%3E
- https://lists.apache.org/thread.html/rdbf1cd0ab330c032f3a09b453cb6405dccc905ad53765323bddab957@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rde11c433675143d8d27551c3d9e821fe1955f1551a518033d3716553@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rde782fd8e133f7e04e50c8aaa4774df524367764eb5b85bf60d96747@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/re08b03cd1754b32f342664eead415af48092c630c8e3e0deba862a26@%3Ccommits.shiro.apache.org%3E
- https://lists.apache.org/thread.html/re5706141ca397587f7ee0f500a39ccc590a41f802fc125fc135cb92f@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rfe6ba83d14545e982400dea89e68b10113cb5202a3dcb558ce64842d@%3Cissues.zookeeper.apache.org%3E
- https://security.netapp.com/advisory/ntap-20201123-0005/
Related Security Bulletins
- Privilege escalation in Eclipse Jetty
- Multiple vulnerabilities in Red Hat AMQ Broker
- Race condition in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Communications Application Session Controller
- Race condition in Oracle FLEXCUBE Core Banking
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in OpenShift Container Platform 3.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.5
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in Oracle Communications Offline Mediation Controller
- Multiple vulnerabilities in Oracle Communications Services Gatekeeper
- Race condition in Siebel Core - Automation
- Debian update for jetty9
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Race condition in IBM Process Mining
- Multiple vulnerabilities in Dell CloudLink
- Multiple vulnerabilities in IBM Storage Protect Server
- Denial of service in BIG-IP and BIG-IQ Centralized Management iControl REST
- Traffix SDC update for Eclipse Jetty
- Multiple vulnerabilities in IBM Storage Scale
- openEuler 20.03 LTS SP1 update for jetty
- Multiple vulnerabilities in IBM Security Directory Integrator
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Business Automation Workflo
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Security Directory Suite
- Multiple vulnerabilities in AMQ Broker 7.4
- Multiple vulnerabilities in IBM Engineering Lifecycle Management - Jazz Foundation