CVE-2021-44138
Path Traversal in Caucho Resin
Record summary
CVE-2021-44138 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.caucho:resinBrowse Maven / com.caucho:resin | GitHub Advisory | 4.0.52 to ≤ 4.0.56 | affected |
Nuclei templates
1ProjectDiscoveryHIGHCaucho Resin >=4.0.52 <=4.0.56 - Directory traversalCVSS 7.5
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.
Impact
An attacker can exploit this vulnerability to read arbitrary files on the server, potentially leading to unauthorized access or sensitive data exposure.
Remediation
Upgrade Caucho Resin to a version higher than 4.0.56 to mitigate the vulnerability.
Source: ProjectDiscovery