CVE-2021-44140

Incorrect Default Permissions in maven/org.apache.jspwiki/jspwiki-main

Identifiers

CVE-2021-44140

Package Slug

maven/org.apache.jspwiki/jspwiki-main

Vulnerability

Incorrect Default Permissions

Description

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance.

Affected Versions

All versions before 2.11.0

Solution

Upgrade to version 2.11.0 or above.

Last Modified

2021-11-30

source