Update CVE-2022-29464.yaml
parent
e9eb4de1ac
commit
d5bd8554e7
|
@ -4,7 +4,8 @@ info:
|
|||
name: WSO2 Management - Arbitrary File Upload & Remote Code Execution
|
||||
author: luci,dhiyaneshDk
|
||||
severity: critical
|
||||
description: Certain WSO2 products allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.
|
||||
description: |
|
||||
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. This affects WSO2 API Manager 2.2.0 and above through 4.0.0; WSO2 Identity Server 5.2.0 and above through 5.11.0; WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0, and 5.6.0; WSO2 Identity Server as Key Manager 5.3.0 and above through 5.10.0; and WSO2 Enterprise Integrator 6.2.0 and above through 6.6.0.
|
||||
reference:
|
||||
- https://shanesec.github.io/2022/04/21/Wso2-Vul-Analysis-cve-2022-29464/
|
||||
- https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2021-1738
|
||||
|
|
Loading…
Reference in New Issue