Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Jetspeed User Manager服务安全漏洞
Vulnerability Description
Apache Jetspeed是美国阿帕奇(Apache)软件基金会的一套使用Java和XML开发的开放门户平台和企业信息门户网站。User Manager service是其中的一个用户管理服务。 Apache Jetspeed 2.3.1之前版本的User Manager服务中存在安全漏洞,该漏洞源于程序没有正确限制使用Jetspeed Security的访问权限。远程攻击者可借助REST API利用该漏洞添加、编辑或删除用户。
CVSS Information
N/A
Vulnerability Type
N/A