{"id":"GHSA-pffw-p2q5-w6vh","summary":"Improper Limitation of a Pathname ('Path Traversal')  in org.apache.jspwiki:jspwiki-war","details":"A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.","aliases":["CVE-2019-0225"],"modified":"2023-11-08T04:00:32.030969Z","published":"2019-04-08T16:23:36Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:49:01Z","nvd_published_at":null,"cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0225"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pffw-p2q5-w6vh"},{"type":"WEB","url":"https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-0225"},{"type":"WEB","url":"https://lists.apache.org/thread.html/03ddbcb1d6322e04734e65805a147a32bcfdb71b8fc5821fb046ba8d@%3Cannounce.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/4f19fdbd8b9c4caf6137a459d723f4ec60379b033ed69277eb4e0af9@%3Cuser.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/6251c06cb11e0b495066be73856592dbd7ed712487ef283d10972831@%3Cdev.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/aac253cfc33c0429b528e2fcbe82d3a42d742083c528f58d192dfd16@%3Ccommits.jspwiki.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/e42d6e93384d4a33e939989cd00ea2a06ccf1e7bb1e6bdd3bf5187c1@%3Ccommits.jspwiki.apache.org%3E"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/03/26/2"},{"type":"WEB","url":"http://www.securityfocus.com/bid/107627"}],"affected":[{"package":{"name":"org.apache.jspwiki:jspwiki-war","ecosystem":"Maven","purl":"pkg:maven/org.apache.jspwiki/jspwiki-war"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.0"},{"fixed":"2.11.0.M3"}]}],"versions":["2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.11.0.M1","2.11.0.M2"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.11.0.M2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-pffw-p2q5-w6vh/GHSA-pffw-p2q5-w6vh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}