CVE-2014-8114

Description

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:U/RC:C
EPSS Score
Exploitation Probability
1.771

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-8114 are affected in Uberfire - uberfire-parent 0.3.1Windows
Vulnerabilities CVE-2014-8114 are affected in Uberfire - uberfire-parent for Linux 0.3.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234