CVE-2021-44140
maven/org.apache.jspwiki/jspwiki-war
Incorrect Default Permissions
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance.
All versions before 2.11.0
Upgrade to version 2.11.0 or above.
2021-11-30
source |