CVE Published: 25/06/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: eclipse |
Vendor: The Eclipse Foundation |
Product: Eclipse BIRT Status : PUBLISHED
CVE-2021-34427 Description
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.