Описание
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
Ссылки
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.19 (включая)
cpe:2.3:a:pascom:cloud_phone_system:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 4.5.0 (исключая)
Одно из
cpe:2.3:a:igniterealtime:openfire:*:*:*:*:*:*:*:*
cpe:2.3:a:igniterealtime:openfire:4.5.0:-:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.8933
Высокий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
EPSS
Процентиль: 100%
0.8933
Высокий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-22