PT-2015-4006 · Uberfire · Uberfire Framework
Publicado
2015-02-20
·
Atualizado
2022-05-14
·
CVE-2014-8114
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
UberFire Framework versions 0.3.x
Description
The issue allows remote attackers to execute arbitrary code by uploading crafted content to "FileUploadServlet" or read arbitrary files via vectors involving "FileDownloadServlet" due to improper path restriction.
Recommendations
For UberFire Framework versions 0.3.x, consider restricting access to the
FileUploadServlet and FileDownloadServlet until a proper fix is applied to prevent arbitrary code execution and unauthorized file access.Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Uberfire Framework