Apache Software Foundation Apache Pluto vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_pluto.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-0186MEDIUMCVSS 6.1PoCv3.0.0v3.0.12019-04-26
CVE-2019-0186 [MEDIUM] CWE-79 CVE-2019-0186: The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cros
The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file
cvelistv5nvd
CVE-2018-1306HIGHCVSS 7.5PoCv3.0.02018-06-27
CVE-2018-1306 [HIGH] CWE-200 CVE-2018-1306: The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 co
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
cvelistv5nvd