The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Http Apache Jetspeed | — | Upgrade Apache Jetspeed-2 to version 2.3.1 or later, which is the final release of the project and contains the fixes for the 2016 security advisories. Note that Apache Jetspeed-2 has been declared dormant (2022) and retired to the Apache Attic (2025), so 2.3.1 is the highest version that will ever ship; migration to a supported portal framework should be considered. | Jun 12, 2026 | Apr 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub