Record summary

CVE-2021-44138 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory4.0.52 to ≤ 4.0.56affected

Nuclei templates

1
ProjectDiscoveryHIGHCaucho Resin >=4.0.52 <=4.0.56 - Directory traversalCVSS 7.5

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

Impact

An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or sensitive data exposure.

Remediation

Upgrade Caucho Resin to a version higher than 4.0.56 to mitigate the vulnerability.

WeaknessesCWE-22
Authorscarrot2
Template tagscve2021cveresincaucholfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:caucho:resin:*:*:*:*:*:*:*:*
Shodan: html:"Resin"
Shodan: http.html:"resin"
Shodan: cpe:"cpe:2.3:a:caucho:resin"
FOFA: body="resin"

Source: ProjectDiscovery

References

2