VulnerabilityModified
CVE-2017-5869
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a ..
HIGH 8.8EPSS 34.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 34.59% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- nuxeo/nuxeo
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2017/03/23/6Exploit, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/97083
- https://sysdream.com/news/lab/2017-03-23-cve-2017-5869-nuxeo-platform-remote-code-execution/
- https://www.exploit-db.com/exploits/41748/
- http://www.openwall.com/lists/oss-security/2017/03/23/6Exploit, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/97083
- https://sysdream.com/news/lab/2017-03-23-cve-2017-5869-nuxeo-platform-remote-code-execution/
- https://www.exploit-db.com/exploits/41748/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.