Rewterz
Rewterz Threat Advisory – Multiple VMware vCenter Server Vulnerabilities
November 24, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-42727 – Adobe RoboHelp Server Directory Traversal
November 24, 2021

Rewterz Threat Advisory – Multiple Apache JSPWiki Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-40369 

Apache JSPWiki is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the Denounce plugin. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2021-44140 

Apache JSPWiki could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted HTTP request on logout, an attacker could exploit this vulnerability to delete arbitrary files in a system hosting a JSPWiki instance.

Impact

  • Cross-SIte Scripting
  • Security Bypass

Affected Vendors

Apache

Affected Products

  • Apache JSPWiki 2.10.0

Remediation

Upgrade to the latest version of Apache JSPWiki, available from the Apache Web site.

https://jspwiki.apache.org/