QID 982317

QID 982317: Java (maven) Security Update for org.apache.jspwiki:jspwiki-war (GHSA-pffw-p2q5-w6vh)

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to GHSA-pffw-p2q5-w6vh for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982317

    Software Advisories
    Advisory ID Software Component Link
    GHSA-pffw-p2q5-w6vh org.apache.jspwiki:jspwiki-war URL Logo github.com/advisories/GHSA-pffw-p2q5-w6vh