peter bassill · operator
$ cve CVE-2021-44140 JSON

CVE-2021-44140

9.1
CRITICAL · CVSS 3.1 · EPSS 6.4% (pctl 93)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS6.36% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-276
On CISA KEVno
Public exploitnone known
Published2021-11-24
Last modified2026-06-17

Affected (1)

VendorProduct
apachejspwiki

References

→ the Explorer  ·  watch your stack  ·  NVD