Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-44140

Опубликовано: 24 нояб. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4
CVSS3: 9.1

Описание

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

РелизСтатусПримечание
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 4 лет назад

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

CVSS3: 9.1
debian
около 4 лет назад

Remote attackers may delete arbitrary files in a system hosting a JSPW ...

CVSS3: 9.1
github
около 4 лет назад

Incorrect Default Permissions in Apache JSPWiki

CVSS3: 9.1
fstec
около 4 лет назад

Уязвимость программного обеспечения на основе JSP технологий Apache JSPWiki, связанная с недостатками разграничения доступа, позволяющая нарушителю удалить произвольные файлы

6.4 Medium

CVSS2

9.1 Critical

CVSS3