Impact
Caucho Resin includes a path traversal flaw in its documentation webapp (resin-doc) that permits attackers to read any file on the system. By sending an unauthenticated HTTP request to the jndi‑appconfig servlet and supplying a relative path containing directory traversal sequences in the inputFile parameter, a remote user can access files outside the intended tutorial directory. This flaw can expose configuration files, credentials, or other sensitive data, potentially leading to privilege escalation or full system compromise.
Affected Systems
The vulnerability affects the Caucho Technology Resin server, specifically the resin-doc documentation application that contains the jndi‑appconfig servlet. No specific version numbers are provided in the advisories, so any deployment that includes the resin-doc webapp is likely susceptible. Administrators should verify whether this servlet is present in their installed Resin environment.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. An attacker only requires network access to the Resin server’s HTTP interface; no user credentials are needed. The exploit is straightforward once the attacker knows the endpoint, and while the EPSS score is not publicly available, the high base score reflects a significant risk. The vulnerability is not listed in CISA’s KEV catalog, but its impact remains substantial.
OpenCVE Enrichment