RHSA-2020:5168MediumCVSS 7.0
Red Hat Security Advisory: rh-eclipse security, bug fix and enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-27216 — jetty: local temporary directory hijacking vulnerability
🎯 Affected products200
- Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-1:4.17-6.el7_9.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-1:4.17-6.el7_9.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-1:4.17-6.el7_9.x86_64 as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-1:4.17-6.el7_9.x86_64 as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-0:1.10.9-1.2.el7.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-0:1.10.9-1.2.el7.src as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-antlr-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-antlr-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-bcel-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-bcel-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-bsf-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-bsf-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-log4j-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-log4j-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-oro-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-oro-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-regexp-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-regexp-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-resolver-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-resolver-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-apache-xalan2-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-apache-xalan2-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-commons-logging-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-commons-logging-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- rh-eclipse-ant-commons-net-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Server (v. 7)
- rh-eclipse-ant-commons-net-0:1.10.9-1.2.el7.noarch as a component of Red Hat Developer Tools for Red Hat Enterprise Linux Workstation (v. 7)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Jetty users should create temp folders outside the normal /tmp structure, and ensure that their permissions are set so as not to be accessible by an attacker.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2020:5168
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_developer_tools/1/html-single/using_eclipse_4.17/index#changes_in_eclipse
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891132
- externalhttps://issues.redhat.com/browse/RHECLIPSE-311
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_5168.json