VDB

CISCO-SA-20181107-STRUTS-COMMONS-FILEUPLOAD

CISCO-SA-20181107-STRUTS-COMMONS-FILEUPLOAD PUBLISHED CVSS 9.300000190734863 CRITICAL

On November 5, 2018, the Apache Struts Team released a security announcement urging an upgrade of the Commons FileUpload library to version 1.3.3 on systems using Struts 2.3.36 or earlier releases. Systems using earlier versions of this library may be exposed to attacks that could allow execution of arbitrary code or modifications of files on the system. The issue is caused by a previously reported vulnerability of the Apache Commons FileUpload library, assigned to CVE-2016-1000031. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this vulnerability by submitting crafted data to an affected system. A successful exploit could allow the attacker to execute arbitrary code or manipulate files on the targeted system.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Timeline

  • Nov 7, 2018 CVE Published
  • Feb 7, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›