Description
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2015-0234.html
http://rhn.redhat.com/errata/RHSA-2015-0235.html
http://www.securityfocus.com/bid/88199
https://github.com/uberfire/uberfire/commit/21ec50eb15
Related Vulnerabilities
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-rt-bindings-soap
CVE-2016-9879 Vulnerability in maven package org.springframework.security:spring-security-web
CVE-2020-27782 Vulnerability in maven package io.undertow:undertow-servlet
CVE-2020-10688 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2016-3093 Vulnerability in maven package org.apache.struts.xwork:xwork-core