CVE-2021-44138

HIGH NUCLEI

Caucho Resin < 4.0.56 - Path Traversal

Title source: rule

Description

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

Nuclei Templates (1)

Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal
HIGHVERIFIEDby carrot2
Shodan: html:"Resin" || http.html:"resin" || cpe:"cpe:2.3:a:caucho:resin"
FOFA: body="resin"

Scores

CVSS v3 7.5
EPSS 0.8163
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
caucho/resin 4.0.52 - 4.0.56
com.caucho/resin 4.0.52Maven
Published Apr 04, 2022
Tracked Since Feb 18, 2026