CVE-2020-27216
Java vulnerability analysis and mitigation

Overview

CVE-2020-27216 affects Eclipse Jetty versions 1.0 through 9.4.32.v20200930, 10.0.0.alpha1 through 10.0.0.beta2, and 11.0.0.alpha1 through 11.0.0.beta2. The vulnerability was discovered in October 2020 and disclosed by security researcher Jonathan Leitschuh (Eclipse Bug, GitHub Advisory).

Technical details

The vulnerability exists in Unix-like systems where the system's temporary directory is shared between all users. A collocated user can observe the process of creating a temporary subdirectory in the shared temporary directory and race to complete the creation before Jetty. The vulnerability has a CVSS v3.1 score of 7.8 (High) with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

If an attacker wins the race condition, they gain read and write permissions to the subdirectory used to unpack web applications, including access to WEB-INF/lib jar files and JSP files. If any code is executed from this temporary directory, this can lead to local privilege escalation. The vulnerability also affects any user code using WebAppContext::getTempDirectory or ServletContext tempdir attributes (GitHub Advisory).

Exploitability

The vulnerability requires local access and can be exploited through a race condition attack on temporary directory creation. The JSP library itself uses the container temp directory for compiling JSP source into Java classes before executing them, making it a potential attack vector (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in versions 9.4.33, 10.0.0.beta3, and 11.0.0.beta3. A workaround is to set a temporary directory, either for the server or the context, to a directory outside of the shared temporary file system. For recent releases, creating a 'work' directory in ${jetty.base} or setting java.io.tmpdir to a secure location can mitigate the issue (GitHub Advisory).

Community reactions

The vulnerability received attention from multiple organizations including Oracle, NetApp, and Debian who issued security advisories and patches for their affected products (Oracle CPU, NetApp Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76904CRITICAL9.8
  • Java logoJava
  • org.geotools.jdbc:gt-jdbc-postgis
NoYesAug 21, 2026
GHSA-mqjf-5f49-2fjhCRITICAL9.8
  • Java logoJava
  • org.geotools:gt-jdbc-postgis
NoYesAug 21, 2026
CVE-2026-54049HIGH8.7
  • Java logoJava
  • org.sakaiproject.conversations:sakai-conversations-impl
NoNoAug 24, 2026
CVE-2026-63202HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-54050MEDIUM6.5
  • Java logoJava
  • org.sakaiproject.profile2:profile2-api
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management