Логотип exploitDog
bind:CVE-2021-34685
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-34685

Количество 2

Количество 2

nvd логотип

CVE-2021-34685

больше 4 лет назад

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-v548-fhp9-qm3w

больше 3 лет назад

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-34685

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

CVSS3: 2.7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-v548-fhp9-qm3w

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу