Описание
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.0 (включая)
cpe:2.3:a:apache:openmeetings:*:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01232
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Apache OpenMeetings allows remote attackers to read arbitrary files by attempting to upload a file
EPSS
Процентиль: 79%
0.01232
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200