Description
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1836)
WordPress Plugin bbPress Security Bypass (2.6.3)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-43952)
WordPress Plugin Product Import Export for WooCommerce Cross-Site Request Forgery (1.7.4)