Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pffw-p2q5-w6vh

Опубликовано: 08 апр. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Limitation of a Pathname ('Path Traversal') in org.apache.jspwiki:jspwiki-war

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

Пакеты

Наименование

org.apache.jspwiki:jspwiki-war

maven
Затронутые версииВерсия исправления

>= 2.9.0, <= 2.11.0.M2

2.11.0.M3

EPSS

Процентиль: 87%
0.03527
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

CVSS3: 7.5
nvd
почти 7 лет назад

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

CVSS3: 7.5
debian
почти 7 лет назад

A specially crafted url could be used to access files under the ROOT d ...

EPSS

Процентиль: 87%
0.03527
Низкий

7.5 High

CVSS3

Дефекты

CWE-22