Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v63-f83x-37x4

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Limitation of a Pathname to a Restricted Directory in Apache ActiveMQ

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

Пакеты

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

>= 5.0.0, <= 5.11.1

5.11.2

EPSS

Процентиль: 100%
0.84408
Высокий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
около 11 лет назад

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

nvd
около 11 лет назад

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

debian
около 11 лет назад

Directory traversal vulnerability in the fileserver upload/download fu ...

fstec
около 11 лет назад

Уязвимость программной платформы Apache ActiveMQ, позволяющая нарушителю создавать JSP-файлы в произвольных директориях

EPSS

Процентиль: 100%
0.84408
Высокий

Дефекты

CWE-22