CVE-2021-44138
HIGH NUCLEICaucho Resin 4.0.52-4.0.56 - Path Traversal via Semicolon in HTTP Request Path
Title source: llmExploitation Summary
CVE-2021-44138 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.
Nuclei Templates (1)
Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
HIGHVERIFIEDby carrot2
Shodan:
html:"Resin" || http.html:"resin" || cpe:"cpe:2.3:a:caucho:resin"
FOFA:
body="resin"
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/maybe-why-not/reponame/issues/2
Scores
CVSS v3
7.5
EPSS
0.1386
EPSS Percentile
96.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
caucho/resin
4.0.52 - 4.0.56
com.caucho/resin
4.0.52Maven
Published
Apr 04, 2022
Tracked Since
Feb 18, 2026