Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet
63Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck y tiene prueba de concepto pública.
ssvc Actcvss 8.7epss 1.0%
de la publicación al arma
Publicada en NVD18 sept
VulnCheck18 sept
probabilidad de explotación
1.0%top 41% de las CVE
explotación observada
síVulnCheck
1 exploit(s) público(s)
Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests with directory traversal sequences to the servlet endpoint to read files outside the intended tutorial directory on the underlying system. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-12-10.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Caucho Technology, Inc. · ResinPoCs públicas encontradas — 1
cve_referenceblkstone.github.io/2017/10/30/resin-attack-vectors/no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://blkstone.github.io/2017/10/30/resin-attack-vectors/https://caucho.com/products/resinhttps://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/vulnerabilities/chanjet-tplus/chanjet-crm-sqli.yamlhttps://www.vulncheck.com/advisories/caucho-resin-resin-doc-unauthenticated-path-traversal-via-jndi-appconfig-servlet