CVE-2016-4314 – org.wso2.carbon.commons:org.wso2.carbon.logging.view.ui
Package
Manager: maven
Name: org.wso2.carbon.commons:org.wso2.carbon.logging.view.ui
Vulnerable Version: >=0 <=4.4.5
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.23258 pctl0.95731
Details
WSO2 Carbon directory traversal vulnerability Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
Metadata
Created: 2022-05-14T02:46:18Z
Modified: 2025-04-22T01:06:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mjww-vqqw-v78q/GHSA-mjww-vqqw-v78q.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-mjww-vqqw-v78q
Finding: F063
Auto approve: 1