CVE-2018-1306
published 2018-06-27CVE-2018-1306: The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive…
PriorityP263high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
43.90%
98.6th percentile
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | pluto | — | — |
| apache_software_foundation | apache_pluto | — | — |
| linux | linux_kernel | >= 3.8.0 < 6.17.2 | 6.17.2 |
Detection & IOCsextracted from sources · hover to see the quote
url/pluto/portal/File%20Upload/__pdPortletV3AnnotatedDemo.MultipartPortlet%21-1517407963%7C0;0/__ac0↗
- →Alert on multipart file upload requests using the HTTP HEAD method to the Pluto portal File Upload portlet endpoint, particularly targeting the MultipartPortlet path. ↗
- →Detect HTTP requests to /pluto/jspshell.jsp with a 'cmd' query parameter, indicating webshell execution post-exploitation. ↗
- ·The exploit uses a fixed multipart boundary value 'XX' and a specific portlet action token (-1517407963) in the URL; these may vary across deployments but serve as fingerprints in the PoC. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
f2fs: fix to do sanity check on node footer for non inode dnode
osv·2025-10-28
CVE-2025-40025 f2fs: fix to do sanity check on node footer for non inode dnode
f2fs: fix to do sanity check on node footer for non inode dnode
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to do sanity check on node footer for non inode dnode
As syzbot reported below:
------------[ cut here ]------------
kernel BUG at fs/f2fs/file.c:1243!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
CPU: 0 UID: 0 PID: 5354 Comm: syz.0.0 Not tainted 6.17.0-rc1-syzkaller-00211-g90d970cade8e #0 PREEMPT(full)
RIP: 0010:f2fs_truncate_hole+0x69e/0x6c0 fs/f2fs/file.c:1243
Call Trace:
f2fs_punch_hole+0x2db/0x330 fs/f2fs/file.c:1306
f2fs_fallocate+0x546/0x990 fs/f2fs/file.c:2018
vfs_fallocate+0x666/0x7e0 fs/open.c:342
ksys_fallocate fs/open.c:366 [inline]
__do_sys_fallocate fs/open.c:371 [inline]
__se_sys_fallocate fs/open.c:369 [inline]
__x64_sys_fallo
OSV
Exposure of Sensitive Information in Apache Pluto
osv·2022-05-14
CVE-2018-1306 [HIGH] Exposure of Sensitive Information in Apache Pluto
Exposure of Sensitive Information in Apache Pluto
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
GHSA
Exposure of Sensitive Information in Apache Pluto
ghsa·2022-05-14
CVE-2018-1306 [HIGH] CWE-200 Exposure of Sensitive Information in Apache Pluto
Exposure of Sensitive Information in Apache Pluto
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
No detection rules found.
2018-06-27
Published