CVE-2017-3188

Source
https://cve.org/CVERecord?id=CVE-2017-3188
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-3188.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-3188
Published
2018-07-24T15:29:00.593Z
Modified
2026-07-08T15:11:16.586820Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly checked, allowing for writing files to arbitrary directories on the file system. These archives may be uploaded directly via the administrator panel, or using the CSRF vulnerability (CVE-2017-3187). An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.

References

Affected packages

Git / github.com/dotcms/core

Affected ranges

Type
GIT
Repo
https://github.com/dotcms/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.7.1"
        }
    ],
    "cpe": "cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*"
}

Affected versions

3.*
3.0
3.5
3.5_Preview01
3.5_Preview02
3.6.0
3.6.1
3.7.1
pre3.*
pre3.5buildrevert

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-3188.json"