QID 994961
Date Published: 2023-08-22
QID 994961: Java (Maven) Security Update for org.uberfire:uberfire-parent (GHSA-6h58-c7r7-g2hw)
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6h58-c7r7-g2hw for updates and patch information.
Vendor References
- GHSA-6h58-c7r7-g2hw -
github.com/advisories/GHSA-6h58-c7r7-g2hw
CVEs related to QID 994961
Software Advisories
| Advisory ID | Software | Component | Link |
|---|