CVE-2014-8114 PUBLISHED

Reported by redhat · Published February 20, 2015

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

Affected Products

VendorProductVersions
n/an/an/a
Mavenorg.uberfire:uberfire-parent0.3.0.Beta5, 0.3.0.Beta5
n/an/an/a, n/a

Timeline

References

Open in Interactive Console →