← back
CVE-2017-20284highobserved exploitationCWE-22

Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet

63Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 8.7epss 1.0%
from disclosure to weapon
Published on NVDSep 18
VulnCheckSep 18
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests with directory traversal sequences to the servlet endpoint to read files outside the intended tutorial directory on the underlying system. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-12-10.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.