Lucene search

K
osvGoogleOSV:GHSA-V49X-8HVM-Q347
HistoryMay 14, 2022 - 1:29 a.m.

Exposure of Sensitive Information in Apache Pluto

2022-05-1401:29:43
Google
osv.dev
6
apache pluto
sensitive information
remote attacker
file upload
vulnerability
configuration data

EPSS

0.924

Percentile

99.0%

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.