CVE-2019-17352 Information
Feb 14, 2021
cve
Description
In JFinal cos before 2019-08-13 as used in JFinal 4.4 there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example a .jsp file may be stored and almost immediately deleted but this deletion step does not occur for certain exceptions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Reference
https://gitee.com/jfinal/cos/commit/5eb23d6e384abaad19faa7600d14c9a2f525946a https://gitee.com/jfinal/cos/commit/8d26eec61f0d072a68bf7393cf3a8544a1112130 https://github.com/jfinal/jfinal/issues/171
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.5
Share on: