CVE-2012-2966
Caucho Quercus, as distributed in Resin, overwrites entries in SERVER superglobal array on basis of POST parameters
EPSS 1.6%
描述
Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.
如何修補 CVE-2012-2966
要修補 CVE-2012-2966,請將受影響套件升級到下列已修補版本。
- Maven/com.caucho:resin—升級至 4.0.29 或更新版本
CVE-2012-2966 正在被利用嗎?
低 — EPSS 為 1.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 4.0.29