Arbitrary File Write The advisory has been revoked - it doesn't affect any version of package org.apache.jackrabbit:jackrabbit-standalone  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Not Defined
EPSS
1.37% (87th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEJACKRABBIT-30651
  • published8 Jun 2014
  • disclosed8 Jun 2014
  • creditUnknown

Introduced: 8 Jun 2014

CVE-2013-2186  (opens in a new tab)
CWE-626  (opens in a new tab)

Overview

org.apache.jackrabbit:jackrabbit-standalone The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.

References