CVE-2017-5869
UnknownEPSS 34.59%
Last modified
CVE-2017-5869 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.. EPSS estimates a 34.59% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nuxeo | Nuxeo | 6.0 |
| Nuxeo | Nuxeo | 7.1 |
| Nuxeo | Nuxeo | 7.2 |
| Nuxeo | Nuxeo | 7.3 |
References
- http://www.openwall.com/lists/oss-security/2017/03/23/6Exploit, Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2017/03/23/6Exploit, Mailing List, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5869?
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.
How severe is CVE-2017-5869?
Severity scoring for CVE-2017-5869 is pending analysis. The EPSS model estimates a 34.59% probability of exploitation in the next 30 days.
How do I fix CVE-2017-5869?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5863Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected…
- CVE-2017-5864Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected…
- CVE-2017-5865The password reset functionality in ownCloud Server before 8…
- CVE-2017-5866The autocomplete feature in the E-Mail share dialog in ownCl…
- CVE-2017-5867ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x bef…
- CVE-2017-5868CRLF injection vulnerability in the web interface in OpenVPN…
- CVE-2017-5870Multiple cross-site scripting (XSS) vulnerabilities in ViMbA…
- CVE-2017-5871Odoo Version <= 8.0-20160726 and Version 9 is affected by: C…
- CVE-2017-5872The TCP/IP networking module in Unisys ClearPath MCP systems…
- CVE-2017-5873Unquoted Windows search path vulnerability in the guest serv…
- CVE-2017-5874CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05E…
- CVE-2017-5875XSS was discovered in dotCMS 3.7.0, with an authenticated at…
Are you affected by CVE-2017-5869?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
