Apache Jetspeed-2是美国阿帕奇(Apache)基金会的一个非常开放和可定制的门户平台。 Apache Jetspeed-2 存在安全漏洞,该漏洞源于Apache Jetspeed-2 在默认情况下没有充分过滤不受信任的用户输入,从而导致一些问题,包括XSS、CSRF、XXE和SSRF。设置配置选项 "xss.filter.post = true "可以缓解这些问题。注意:Apache Jetspeed是Apache Portals的一个休眠项目,将不会为这个问题提供更新。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Portals | Jetspeed 2.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-37839 | Improper access to dataset metadata information | |
| CVE-2022-33980 | Apache Commons Configuration insecure interpolation defaults |
No comments yet