apache pluto CVE-2018-1306 is a vulnerability in Apache Pluto
Published on June 27, 2018

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.

NVD


Products Associated with CVE-2018-1306

Want to know whenever a new CVE is published for Apache Pluto? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Pluto Version 3.0.0 is affected by CVE-2018-1306

Exploit Probability

EPSS
65.19%
Percentile
98.46%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.