Описание
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Комментарий
Per Apache: "Having reviewed your report we have concluded that it does not represent a valid vulnerability in Apache Commons File Upload. If an application deserializes data from an untrusted source without filtering and/or validation that is an application vulnerability not a vulnerability in the library a potential attacker might leverage."
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation ...
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2