Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-34427

Опубликовано: 22 авг. 2018
Источник: redhat
CVSS3: 8.8

Описание

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

A flaw was found in eclipse-birt. An attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

This flaw does not affect eclipse-birt as shipped with Red Hat Enterprise Linux 6 because the vulnerable component of birt is not shipped; the shipped package does not contain the affected viewer component.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6eclipse-birtNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1977028eclipse-birt: an attacker can use query parameters to create a JSP file and inject JSP code into the running instance

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

CVSS3: 9.8
github
больше 3 лет назад

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

8.8 High

CVSS3