CVE-2019-0225: Path Traversal
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0225?
CVE-2019-0225 is a vulnerability that allows an attacker to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, potentially exposing registered users' details.
What is the severity of CVE-2019-0225?
CVE-2019-0225 has a severity rating of 7.5, which is considered high.
How does CVE-2019-0225 impact Apache JSPWiki?
CVE-2019-0225 allows an attacker to exploit a specially crafted URL to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, potentially exposing users' details.
How can an attacker exploit CVE-2019-0225?
An attacker can exploit CVE-2019-0225 by using a specially crafted URL to access files under the ROOT directory of the Apache JSPWiki application.
How can I protect my Apache JSPWiki application from CVE-2019-0225?
To protect your Apache JSPWiki application from CVE-2019-0225, it is recommended to update to a version higher than 2.11.0.M2.