Skip to content

Java: Arbitrary user-controlled read/write on user-controlled path #839

Closed
@intrigus-lgtm

Description

@intrigus-lgtm

CVE(s) ID list

  • CVE-2020-15097 (9.1 CRITICAL)
  • CVE-2020-4039 (9.1 CRITICAL)

All For One submission

#136

Details

This has been originally found on lgtm.com
As it has been shut down, I can not provide links to it, so I have to create new dbs.
This will take some time.

Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).

  • Yes
  • No

Blog post link

https://intrigus.org/advisories/2021/07/19/ISL-2020-002-loklak-loklak_server/ https://intrigus.org/advisories/2021/07/19/ISL-2020-001-fossasia-susiserver/

Metadata

Metadata

Assignees

No one assigned

    Labels

    The Bug SlayerSubmissions to The Bug Slayer bounty

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions