{"id":"CVE-2021-44140","details":"Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.","aliases":["GHSA-8gw6-w5rw-4g5c"],"modified":"2026-07-09T01:08:00.085640Z","published":"2021-11-24T12:15:07.663Z","references":[{"type":"ADVISORY","url":"https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2021-44140"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/5qglpjdhvobppx7j550lf1sk28f6011t"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/jspwiki","events":[{"introduced":"0"},{"fixed":"b9c3d919beee3a73ffd87cde5021327d3a6544a5"}],"database_specific":{"cpe":"cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.11.0"}],"source":"CPE_RANGE"}}],"versions":["2.11.0-RC1","2.11.0.M8-RC1","2.11.0.M8","2.11.0.M7-RC1","2.11.0.M7","2.11.0.M6-RC1","2.11.0.M6","2.11.0.M5-RC3","2.11.0.M5","2.11.0.M5-RC2","2.11.0.M5-RC1","2.11.0.M4-RC2","2.11.0.M4","2.11.0.M4-RC1","2.11.0.M3-RC2","2.11.0.M3","2.11.0.M3-RC1","2.11.0.M2-RC1","2.11.0.M2","2.11.0.M1.RC3","2.11.0.M1","2.11.0.M1-RC2","2.11.0.M1-RC1","2.10.5-RC2","2.10.5","2.10.5-RC1","2.10.4-RC3","2.10.4","2.10.4-RC2","2.10.4-RC1","2.10.3-RC2","2.10.3","2.10.3-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44140.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}