CVE-2019-17352 Information

Description

In JFinal cos before 2019-08-13 as used in JFinal 4.4 there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example a .jsp file may be stored and almost immediately deleted but this deletion step does not occur for certain exceptions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

https://gitee.com/jfinal/cos/commit/5eb23d6e384abaad19faa7600d14c9a2f525946a https://gitee.com/jfinal/cos/commit/8d26eec61f0d072a68bf7393cf3a8544a1112130 https://github.com/jfinal/jfinal/issues/171

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: