{"id":"CVE-2017-5869","details":"Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.","modified":"2026-07-08T14:14:31.885606Z","published":"2017-03-24T14:59:00.303Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/97083"},{"type":"WEB","url":"https://sysdream.com/news/lab/2017-03-23-cve-2017-5869-nuxeo-platform-remote-code-execution/"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/41748/"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2017/03/23/6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nuxeo/nuxeo","events":[{"introduced":"6b3534563d614ecc4633270780c870991688ca0c"},{"last_affected":"368e49ffd1f0376d7665838138ea6d3d7d16b082"}],"database_specific":{"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"7.1"},{"last_affected":"7.1"},{"introduced":"7.2"},{"last_affected":"7.2"},{"introduced":"7.3"},{"last_affected":"7.3"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:nuxeo:nuxeo:6.0:*:*:*:*:*:*:*","cpe:2.3:a:nuxeo:nuxeo:7.1:*:*:*:*:*:*:*","cpe:2.3:a:nuxeo:nuxeo:7.2:*:*:*:*:*:*:*","cpe:2.3:a:nuxeo:nuxeo:7.3:*:*:*:*:*:*:*"]}}],"versions":["6.0","7.1","7.2","7.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5869.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}