Lucene search

K
githubGitHub Advisory DatabaseGHSA-3V63-F83X-37X4
HistoryMay 14, 2022 - 1:14 a.m.

Improper Limitation of a Pathname to a Restricted Directory in Apache ActiveMQ

2022-05-1401:14:51
CWE-22
GitHub Advisory Database
github.com
22
apache activemq
directory traversal
windows
vulnerability
fileserver
blob messages

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.069

Percentile

94.0%

Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

Affected configurations

Vulners
Node
org.apache.activemqactivemq-clientRange5.0.05.11.1
VendorProductVersionCPE
org.apache.activemqactivemq-client*cpe:2.3:a:org.apache.activemq:activemq-client:*:*:*:*:*:*:*:*

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.069

Percentile

94.0%