漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
hs-web hsweb-framework File Upload FileUploadProperties.java denied path traversal
Vulnerability Description
A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 8009845b577d8a2c4bbf4fdd8e8913799a714be6. It is suggested to install a patch to address this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
hsweb4 路径遍历漏洞
Vulnerability Description
hsweb4是hs-web开源的一个基于Spring Boot 2的全响应式后台管理框架。 hsweb4 5.0.1及之前版本存在路径遍历漏洞,该漏洞源于文件上传组件中文件hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java的denied函数对参数filename操作不当,可能导致路径遍历。攻击者可远程利用。
CVSS Information
N/A
Vulnerability Type
N/A