PT-2021-14562 · Apache · Servicecomb Servicecenter

Willem Jiang

·

Published

2021-08-10

·

Updated

2021-09-01

·

CVE-2021-21501

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ServiceComb ServiceCenter versions 1.x.x through 1.x.x
Description The issue is caused by improper configuration, leading to a Directory Traversal problem in ServiceCenter. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the fact that improper configuration can cause the problem.
Recommendations For versions 1.x.x, update to version 2.0.0 to resolve the issue. At the moment, there is no other information about additional mitigation measures.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21501
GHSA-X6JV-5VFG-GM7X

Affected Products

Servicecomb Servicecenter