CVE-2021-44140 Information
Jun 07, 2022
cve
Description
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance versions up to 2.11.0.M8 by using a carefuly crafted http request on logout given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Reference
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-44140 https://lists.apache.org/thread/5qglpjdhvobppx7j550lf1sk28f6011t
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.1
Share on: