Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6h58-c7r7-g2hw

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

UberFire Framework Improperly Restricts Paths

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

Пакеты

Наименование

org.uberfire:uberfire-parent

maven
Затронутые версииВерсия исправления

>= 0.3.0.Beta5, <= 0.3.1.Final

Отсутствует

EPSS

Процентиль: 82%
0.01771
Низкий

Дефекты

CWE-22

Связанные уязвимости

redhat
почти 11 лет назад

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

nvd
почти 11 лет назад

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

EPSS

Процентиль: 82%
0.01771
Низкий

Дефекты

CWE-22