CVE-2014-8114 Information
Feb 14, 2021
cve
Description
The UberFire Framework 0.3.x does not properly restrict paths which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.
Reference
http://rhn.redhat.com/errata/RHSA-2015-0234.html http://rhn.redhat.com/errata/RHSA-2015-0235.html http://www.securityfocus.com/bid/88199 https://github.com/uberfire/uberfire/commit/21ec50eb15
Share on: