GHSA-8gw6-w5rw-4g5c
Dashboard / Vulnerabilities / GHSA-8gw6-w5rw-4g5c
Summary: Incorrect Default Permissions in Apache JSPWiki
Details: Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-44140, https://github.com/apache/jspwiki, https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-44140, https://lists.apache.org/thread/5qglpjdhvobppx7j550lf1sk28f6011t
Affected packages
Package
Name: org.apache.jspwiki:jspwiki-main
Purl: pkg:maven/org.apache.jspwiki/jspwiki-main
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.11.0
Affected versions
2.11.0.M1
2.11.0.M2
2.11.0.M3
2.11.0.M4
2.11.0.M5
2.11.0.M6
2.11.0.M7
2.11.0.M8
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
