Description
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1930 | In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions. |
Github GHSA |
GHSA-279p-pc38-xx4p | JFinal file validation vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:40:15.118Z
Reserved: 2019-10-08T00:00:00.000Z
Link: CVE-2019-17352
No data.
Status : Modified
Published: 2019-10-08T13:15:15.957
Modified: 2024-11-21T04:32:09.077
Link: CVE-2019-17352
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA