[ CVE-2018-1306 ] Apache Portals Pluto information disclosure vulnerability

"Martin Scott Nicklous" <[email protected]> Tue, 26 Jun 2018 14:06:17 +0200
Newsgroups gmane.comp.jakarta.pluto.devel,gmane.comp.security.oss.general,gmane.comp.jakarta.pluto.user
Message-ID <OF86D0194F.A1B3DF32-ONC12582B8.003C8D37-C12582B8.00427E73@notes.na.collabserv.com>
--0__=4EBB082BDFAF0BA78f9e8a93df938690918c4EBB082BDFAF0BA7
Content-Transfer-Encoding: quoted-printable
Content-type: text/plain; charset=ISO-8859-1



Affected Product: Apache Pluto

Severity: Important

Vendor: The Apache Software Foundation

CVEID: CVE-2018-1306

DESCRIPTION: The PortletV3AnnotatedDemo Multipart Portlet war file code
could allow a remote attacker to obtain sensitive information, caused by
the failure to restrict path information provided during a file upload. An
attacker could exploit this vulnerability to obtain configuration data and
other sensitive information.

Versions Affected:
3.0.0

Mitigation:
* Uninstall the  PortletV3AnnotatedDemo Multipart Portlet war file
- or -
* migrate to version 3.0.1

Credit:
Che-Chun Kuo

Mit freundlichen Gr=FC=DFen, / Kind regards,
Scott Nicklous

WebSphere Portal Standardization Lead & Technology Consultant
Specification Lead, JSR 362 Portlet Specification 3.0
IBM Commerce, Digital Experience Development

Phone: +49-7031-16-4808 / E-Mail:[email protected] /  Schoenaicher
Str. 220, 71032 Boeblingen, Germany
IBM Deutschland Research & Development GmbH / Vorsitzender des
Aufsichtsrats: Martina Koederitz / Gesch=E4ftsf=FChrung: Dirk Wittkopp
Sitz der Gesellschaft: B=F6blingen / Registergericht: Amtsgericht Stuttgart,
HRB 243294

--0__=4EBB082BDFAF0BA78f9e8a93df938690918c4EBB082BDFAF0BA7
Content-Transfer-Encoding: quoted-printable
Content-type: text/html; charset=ISO-8859-1
Content-Disposition: inline

<html><body><p><font size=3D"2">Affected Product: Apache Pluto</font><br><b=
r><font size=3D"2">Severity: Important</font><br><br><font size=3D"2">Vendo=
r: </font><font size=3D"2">The Apache Software Foundation</font><br><br><fo=
nt size=3D"2">CVEID: </font>CVE-2018-1306<font size=3D"2"> </font><br><br><=
font size=3D"2">DESCRIPTION: The PortletV3AnnotatedDemo Multipart Portlet w=
ar file code could allow a remote attacker to obtain sensitive information,=
 caused by the failure to restrict path information provided during a file =
upload. An attacker could exploit this vulnerability to obtain configuratio=
n data and other sensitive information. </font><br><br><font size=3D"2">Ver=
sions Affected:</font><br><font size=3D"2">3.0.0</font><br><br><font size=
=3D"2">Mitigation:</font><br><font size=3D"2">* Uninstall the  PortletV3Ann=
otatedDemo Multipart Portlet war file </font><br><font size=3D"2">- or -</f=
ont><br><font size=3D"2">* migrate to version 3.0.1</font><br><br><font siz=
e=3D"2">Credit:</font><br><font size=3D"2">Che-Chun Kuo</font><br><font siz=
e=3D"2"><br>Mit freundlichen Gr=FC=DFen, / Kind regards,<br>Scott Nicklous<=
br><br>WebSphere Portal Standardization Lead &amp; Technology Consultant<br=
>Specification Lead, JSR 362 Portlet Specification 3.0<br>IBM Commerce, Dig=
ital Experience Development<br><br>Phone: +49-7031-16-4808 / E-Mail:scott.n=
[email protected] /  Schoenaicher Str. 220, 71032 Boeblingen, Germany <br>=
IBM Deutschland Research &amp; Development GmbH / Vorsitzender des Aufsicht=
srats: Martina Koederitz / Gesch=E4ftsf=FChrung: Dirk Wittkopp <br>Sitz der=
 Gesellschaft: B=F6blingen / Registergericht: Amtsgericht Stuttgart, HRB 24=
3294 <br></font><BR>
</body></html>

--0__=4EBB082BDFAF0BA78f9e8a93df938690918c4EBB082BDFAF0BA7--