Description
Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests with directory traversal sequences to the servlet endpoint to read files outside the intended tutorial directory on the underlying system. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-12-10.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Disclosure
Action: Apply Patch
AI Analysis

Impact

Caucho Resin includes a path traversal flaw in its documentation webapp (resin-doc) that permits attackers to read any file on the system. By sending an unauthenticated HTTP request to the jndi‑appconfig servlet and supplying a relative path containing directory traversal sequences in the inputFile parameter, a remote user can access files outside the intended tutorial directory. This flaw can expose configuration files, credentials, or other sensitive data, potentially leading to privilege escalation or full system compromise.

Affected Systems

The vulnerability affects the Caucho Technology Resin server, specifically the resin-doc documentation application that contains the jndi‑appconfig servlet. No specific version numbers are provided in the advisories, so any deployment that includes the resin-doc webapp is likely susceptible. Administrators should verify whether this servlet is present in their installed Resin environment.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating high severity. An attacker only requires network access to the Resin server’s HTTP interface; no user credentials are needed. The exploit is straightforward once the attacker knows the endpoint, and while the EPSS score is not publicly available, the high base score reflects a significant risk. The vulnerability is not listed in CISA’s KEV catalog, but its impact remains substantial.

Generated by OpenCVE AI on September 19, 2026 at 10:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Resin version that removes the resin-doc webapp or patches the jndi‑appconfig servlet.
  • If an update is unavailable, disable or remove the resin-doc webapp and the jndi‑appconfig servlet from the server to eliminate the attack surface.
  • Restrict external network access to the Resin HTTP interface using firewall rules or network segmentation so that the vulnerable endpoint is not reachable from untrusted hosts.
  • Enable logging and monitoring of file access patterns or failed attempts to detect accidental or malicious exploitation.

Generated by OpenCVE AI on September 19, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Caucho Technology
Caucho Technology resin
Vendors & Products Caucho Technology
Caucho Technology resin

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests with directory traversal sequences to the servlet endpoint to read files outside the intended tutorial directory on the underlying system. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-12-10.
Title Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Caucho Technology Resin
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:46:26.546Z

Reserved: 2026-09-18T18:15:16.616Z

Link: CVE-2017-20284

cve-icon Vulnrichment

Updated: 2026-09-18T19:46:20.765Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:16:58.540

Modified: 2026-09-22T20:25:55.870

Link: CVE-2017-20284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')