RHSA-2020:5168MediumCVSS 7.0

Red Hat Security Advisory: rh-eclipse security, bug fix and enhancement update

Published
November 23, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2020-27216 — jetty: local temporary directory hijacking vulnerability

🎯 Affected products200

  • Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-1:4.17-6.el7_9.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-1:4.17-6.el7_9.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-1:4.17-6.el7_9.x86_64 as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-1:4.17-6.el7_9.x86_64 as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-0:1.10.9-1.2.el7.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-0:1.10.9-1.2.el7.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-antlr-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-antlr-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-bcel-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-bcel-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-bsf-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-bsf-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-log4j-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-log4j-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-oro-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-oro-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-regexp-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-regexp-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-resolver-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-resolver-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-apache-xalan2-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-apache-xalan2-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-commons-logging-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-commons-logging-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • rh-eclipse-ant-commons-net-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
  • rh-eclipse-ant-commons-net-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Jetty users should create temp folders outside the normal /tmp structure, and ensure that their permissions are set so as not to be accessible by an attacker.

🔗 References (6)