Lucene search

K
redhatRedHatRHSA-2013:1442
HistoryOct 17, 2013 - 5:17 p.m.

(RHSA-2013:1442) Important: commons-fileupload security update

2013-10-1717:17:19
access.redhat.com
20

0.019 Low

EPSS

Percentile

88.6%

The Apache Commons FileUpload component can be used to add a file upload
capability to your applications.

A flaw was found in the way the DiskFileItem class handled NULL characters
in file names. A remote attacker able to supply a serialized instance of
the DiskFileItem class, which will be deserialized on a server, could use
this flaw to write arbitrary content to any location on the server that is
accessible to the user running the application server process.
(CVE-2013-2186)

All users of the affected products as provided from the Red Hat Customer
Portal are advised to apply this update.