GHSA-g5fx-ccwv-5c4f

Suggest an improvement
Source
https://github.com/advisories/GHSA-g5fx-ccwv-5c4f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g5fx-ccwv-5c4f/GHSA-g5fx-ccwv-5c4f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g5fx-ccwv-5c4f
Aliases
  • CVE-2012-2966
Published
2022-05-17T05:23:56Z
Modified
2025-04-12T03:57:07.230389Z
Summary
Caucho Quercus, as distributed in Resin, overwrites entries in SERVER superglobal array on basis of POST parameters
Details

Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-12T02:55:51Z",
    "nvd_published_at": "2012-08-12T16:55:00Z",
    "severity": "HIGH",
    "cwe_ids": []
}
References

Affected packages

Maven / com.caucho:resin

Package

Name
com.caucho:resin
View open source insights on deps.dev
Purl
pkg:maven/com.caucho/resin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.29

Affected versions

3.*
3.0.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g5fx-ccwv-5c4f/GHSA-g5fx-ccwv-5c4f.json"