Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • How to Protect Your Data When Ransomware Strikes cyber security news
  • Microsoft Discovers New Privilege Escalation Flaws in Linux Operating System cyber security news
  • Bitcoin Taker Buy/Sell Ratio Approaches Bullish Cross bitcoin news
  • Tesla CEO Elon Musk Gives Investment Advice He Says ‘Will Serve You Well in the Long Term’ – Featured Bitcoin News bitcoin news
  • Gamestop Launches Web3 Ethereum Wallet That Leverages Loopring’s ZK-Rollup Tech – Bitcoin News bitcoin news
  • ETH Co-Founder Vitalik Buterin Says The Merge Could Happen in August, There’s Also ‘Risk of Delay’ – Bitcoin News bitcoin news
  • Collectors and Enthusiasts Can Now Turn Their Image and Likeness into Eye-popping NFTs with Onliners Metaverse bitcoin news
  • BTC, ETH Marginally Higher Ahead of Today’s Rate Decision – Market Updates Bitcoin News bitcoin news

Critical RCE Bug Reported in dotCMS Content Management Software

Posted on May 4, 2022 By root


dotCMS Content Management Software

A pre-authenticated remote code execution vulnerability has been disclosed in dotCMS, an open-source content management system written in Java and “used by over 10,000 clients in over 70 countries around the globe, from Fortune 500 brands and mid-sized businesses.”

The critical flaw, tracked as CVE-2022-26352, stems from a directory traversal attack when performing file uploads, enabling an adversary to execute arbitrary commands on the underlying system.

“An attacker can upload arbitrary files to the system,” Shubham Shah of Assetnote said in a report. “By uploading a JSP file to the tomcat’s root directory, it is possible to achieve code execution, leading to command execution.”

In other words, the arbitrary file upload flaw can be abused to replace already existing files in the system with a web shell, which can then be used to gain persistent remote access.

dotCMS Content Management Software

Although the exploit made it possible to write to arbitrary JavaScript files being served by the application, the researchers said the nature of the bug was such that it could be weaponized to gain command execution.

AssetNote said it discovered and reported the flaw on February 21, 2022, following which patches have been released in versions 22.03, 5.3.8.10, and 21.06.7.

CyberSecurity

“When files are uploaded into dotCMS via the content API, but before they become content, dotCMS writes the file down in a temp directory,” the company said. “In the case of this vulnerability, dotCMS does not sanitize the filename passed in via the multipart request header and thus does not sanitize the temp file’s name.”

“In the case of this exploit, an attacker can upload a special .jsp file to the webapp/ROOT directory of dotCMS which can allow for remote code execution,” it noted.





TheHackersNews/

cyber security news

Post navigation

Previous Post: The Secret for Creating DeFi Content “Your Dad Could Understand” – Interview Bitcoin News
Next Post: El Salvador’s Bitcoin Volcano Bonds Launch Still on Hold, According to Treasury Minister – Bitcoin News

Related Posts

  • Emotet Testing New Delivery Ideas After Microsoft Disables VBA Macros by Default cyber security news
  • UpdateAgent Returns with New macOS Malware Dropper Written in Swift cyber security news
  • GitHub Says Recent Attack Involving Stolen OAuth Tokens Was “Highly Targeted” cyber security news
  • Researchers Uncover Rust Supply-Chain Attack Targeting Cloud CI Pipelines cyber security news
  • New Chaos Ransomware Builder Variant “Yashma” Discovered in the Wild cyber security news
  • QNAP Urges Users to Update NAS Devices to Prevent Deadbolt Ransomware Attacks cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • How Ethereum Uniswap Reached A Milestone Of $1T In Trading Volume
  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys

Recent Comments

No comments to show.
  • Bitcoin Bloodbath Awakens Sleepy Giant As Spot Volumes Surge bitcoin news
  • US, UK, Canada, Australia, Netherlands Share Crypto Criminal Leads, Including a Potential $1B Ponzi Scheme – Regulation Bitcoin News bitcoin news
  • Global Metaverse Event of Lydian․World in Dubai Opera 7th May 2022 bitcoin news
  • Bitcoin Remains Fragile, What’s The Next Major Support Area? bitcoin news
  • How to Protect Your Data When Ransomware Strikes cyber security news
  • Aloha Browser Paves the Way Towards Web3 With Recent HNS Integration – Press release Bitcoin News bitcoin news
  • Conti Ransomware Gang Shut Down After Splitting into Smaller Groups cyber security news
  • Taki Enters The Indian Market with First of its Kind Engage-to-Earn Crypto Economy bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme