CVE-2021-44140

CRITICAL

Apache JSPWiki < 2.11.0 - Arbitrary File Deletion via Logout Request

Title source: llm
STIX 2.1

Description

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

References (2)

Core 2
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/5qglpjdhvobppx7j550lf1sk28f6011t

Scores

CVSS v3 9.1
EPSS 0.0587
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-276
Status published
Products (2)
apache/jspwiki < 2.11.0
org.apache.jspwiki/jspwiki-main 0 - 2.11.0Maven
Published Nov 24, 2021
Tracked Since Feb 18, 2026