Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v548-fhp9-qm3w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

EPSS

Процентиль: 83%
0.0197
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 2.7
nvd
больше 4 лет назад

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

EPSS

Процентиль: 83%
0.0197
Низкий

Дефекты

CWE-434