oss-sec mailing list archives

[CVE-2019-0225] Apache JSPWiki Local File Inclusion (limited ROOT folder) vulnerability leads to user information disclosure


From: Juan Pablo Santos Rodríguez <juanpablo () apache org>
Date: Tue, 26 Mar 2019 22:43:09 +0100

[CVEID]:CVE-2019-0225
[PRODUCT]:Apache JSPWiki
[VERSION]:Apache JSPWiki 2.9.0 to 2.11.0.M2
[PROBLEMTYPE]:Local File Inclusion (limited ROOT folder) vulnerability
leads to user information disclosure
[REFERENCES]:https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-0225
[DESCRIPTION]: A specially crafted url could be used to access files under
the ROOT directory of the application on Apache JSPWiki, which could be
used by an attacker to obtain registered users' details.

Current thread: