CVE-2014-8114
UberFire Framework 0.3.x - Remote Code Execution and Arbitrary File Read via FileUploadServlet and FileDownloadServlet
Title source: llmDescription
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0234.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0235.html
Patch x_refsource_confirm
https://github.com/uberfire/uberfire/commit/21ec50eb15
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/88199
Scores
EPSS
0.0310
EPSS Percentile
86.4%
Details
CWE
CWE-264
Status
published
Products (5)
org.uberfire/uberfire-parent
0.3.0.Beta5Maven
redhat/uberfire
0.3.0
redhat/uberfire
0.3.1
redhat/uberfire
0.3.2
redhat/uberfire
0.3.3
Published
Feb 20, 2015
Tracked Since
Feb 18, 2026