{"id":"GHSA-h6c8-x5r3-pm88","summary":"Apache Tomcat Unrestricted file upload vulnerability","details":"Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.","aliases":["CVE-2013-4444"],"modified":"2024-12-02T05:36:15.954049Z","published":"2022-05-13T01:12:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-17T22:16:37Z","nvd_published_at":"2014-09-12T01:55:00Z","cwe_ids":["CWE-94"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4444"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04851013"},{"type":"WEB","url":"http://archives.neohapsis.com/archives/bugtraq/2014-09/0075.html"},{"type":"WEB","url":"http://marc.info/?l=bugtraq&m=144498216801440&w=2"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/10/24/12"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2021/Jan/23"},{"type":"WEB","url":"http://tomcat.apache.org/security-7.html"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3447"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/69728"},{"type":"WEB","url":"http://www.securitytracker.com/id/1030834"}],"affected":[{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0"},{"fixed":"7.0.40"}]}],"versions":["7.0.35","7.0.37","7.0.39"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h6c8-x5r3-pm88/GHSA-h6c8-x5r3-pm88.json"}}],"schema_version":"1.9.0"}