CVE-2021-44138
HIGH NUCLEICaucho Resin < 4.0.56 - Path Traversal
Title source: ruleDescription
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.
Nuclei Templates (1)
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
HIGHVERIFIEDby carrot2
Shodan:
html:"Resin" || http.html:"resin" || cpe:"cpe:2.3:a:caucho:resin"
FOFA:
body="resin"
Scores
CVSS v3
7.5
EPSS
0.8163
EPSS Percentile
99.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
caucho/resin
4.0.52 - 4.0.56
com.caucho/resin
4.0.52Maven
Published
Apr 04, 2022
Tracked Since
Feb 18, 2026