CVE-2020-27218: Apache Kafka
Medium severity, CVSS 4.8. EPSS: 8.3% chance of exploitation in the next 30 days.
In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.
Affected products
- Apache Kafka: version 2.7.0 only
- Apache Spark: version 2.4.8 only; version 3.0.3 only
- Debian Debian Linux: version 10.0 only
- Eclipse Jetty: from 9.4.0, before 9.4.35 (fixed in 9.4.35); version 10.0.0 only; version 11.0.0 only
- Netapp Oncommand System Manager: from 3.0, up to and including 3.1.3
- Netapp Snap Creator Framework: affected versions not specified
- Oracle Blockchain Platform: before 21.1.2 (fixed in 21.1.2)
- Oracle Communications Converged Application Server - Service Controller: version 6.2 only
- Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
- Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
- Oracle Communications Services Gatekeeper: version 7.0 only
- Oracle Communications Session Route Manager: from 8.0.0, up to and including 8.2.4
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Hyperion Infrastructure Technology: version 11.1.2.6.0 only
- Oracle Rest Data Services: before 20.4.3.050.1904 (fixed in 20.4.3.050.1904)
- Oracle Retail Eftlink: version 20.0.0 only
- Oracle Siebel Core - Automation: up to and including 21.5
Published 2020-11-28. Last modified 2026-06-17.