PT-2021-5953 · Apache · Apache Jspwiki

Haby0

·

Published

2021-11-23

·

Updated

2021-11-29

·

CVE-2021-44140

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache JSPWiki versions up to 2.11.0.M8
Description The issue is related to inadequate access control in Apache JSPWiki, allowing remote attackers to delete arbitrary files on a system hosting a JSPWiki instance by using a carefully crafted HTTP request on logout. This is possible if the files are reachable to the user running the JSPWiki instance.
Recommendations For Apache JSPWiki versions up to 2.11.0.M8, upgrade to 2.11.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00470
CVE-2021-44140
GHSA-8GW6-W5RW-4G5C

Affected Products

Apache Jspwiki