PT-2021-14562 · Apache · Servicecomb Servicecenter
Willem Jiang
·
Published
2021-08-10
·
Updated
2021-09-01
·
CVE-2021-21501
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ServiceComb ServiceCenter versions 1.x.x through 1.x.x
Description
The issue is caused by improper configuration, leading to a Directory Traversal problem in ServiceCenter. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the fact that improper configuration can cause the problem.
Recommendations
For versions 1.x.x, update to version 2.0.0 to resolve the issue.
At the moment, there is no other information about additional mitigation measures.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Servicecomb Servicecenter