PT-2015-4006 · Uberfire · Uberfire Framework
Published
2015-02-20
·
Updated
2022-05-14
·
CVE-2014-8114
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
UberFire Framework versions 0.3.x
Description
The issue allows remote attackers to execute arbitrary code by uploading crafted content to "FileUploadServlet" or read arbitrary files via vectors involving "FileDownloadServlet" due to improper path restriction.
Recommendations
For UberFire Framework versions 0.3.x, consider restricting access to the
FileUploadServlet and FileDownloadServlet until a proper fix is applied to prevent arbitrary code execution and unauthorized file access.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uberfire Framework