Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."
CVSS Details
- CVSS 3.0 Base Score: 7.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Http Apache Jetspeed | — | Upgrade Apache Jetspeed-2 to version 2.3.1 or later, which is the final release of the project and contains the fixes for the 2016 security advisories. Note that Apache Jetspeed-2 has been declared dormant (2022) and retired to the Apache Attic (2025), so 2.3.1 is the highest version that will ever ship; migration to a supported portal framework should be considered. | Jun 12, 2026 | Apr 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub