SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0300

gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and…

MEDIUM 5.0EPSS 7.33%

Does this matter?

Lower severity and a low EPSS score (7.33%). Track it; it rarely justifies an emergency change on its own.

Description

gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.33% probability · 94th percentile
CISA KEV
Not listed
Affected
gnujsp/gnujsp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.