peter bassill · operator
$ cve CVE-2017-5869 JSON

CVE-2017-5869 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 34.6% (pctl 98)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS34.59% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2017-03-24
Last modified2026-06-17

Affected (1)

VendorProduct
nuxeonuxeo

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD