CVE-2021-44138

HIGH NUCLEI

Caucho Resin 4.0.52-4.0.56 - Path Traversal via Semicolon in HTTP Request Path

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-44138 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

Nuclei Templates (1)

Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
HIGHVERIFIEDby carrot2
Shodan: html:"Resin" || http.html:"resin" || cpe:"cpe:2.3:a:caucho:resin"
FOFA: body="resin"

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/maybe-why-not/reponame/issues/2

Scores

CVSS v3 7.5
EPSS 0.1386
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
caucho/resin 4.0.52 - 4.0.56
com.caucho/resin 4.0.52Maven
Published Apr 04, 2022
Tracked Since Feb 18, 2026