Описание
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libcommons-fileupload-java | unfixed | package |
Примечания
https://www.tenable.com/security/research/tra-2016-12
Marked as unimportant since even though the CVE is assigned for Apache Commons FileUpload
Apache say that issue needs to be fixed in any vendor/product using Apache Commons FileUpload
DiskFileItem as described in the given advisory.
Thus we are not going to diverge from Apache upstream here.
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 9 лет назад
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
CVSS3: 7.3
redhat
почти 10 лет назад
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
CVSS3: 9.8
nvd
больше 9 лет назад
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution