CVE-2019-0225
Summary
| CVE | CVE-2019-0225 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-28 22:29:00 UTC |
| Updated | 2023-11-07 03:01:00 UTC |
| Description | A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Vendor Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Vendor Advisory |
| JSPWiki: CVE-2019-0225 |
CONFIRM |
jspwiki-wiki.apache.org |
Vendor Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Apache JSPWiki CVE-2019-0225 Information Disclosure Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Patch, Vendor Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Patch, Vendor Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Vendor Advisory |
| oss-security - [CVE-2019-0225] Apache JSPWiki Local File Inclusion (limited ROOT
folder) vulnerability leads to user information disclosure |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982317 Java (maven) Security Update for org.apache.jspwiki:jspwiki-war (GHSA-pffw-p2q5-w6vh)