RULE(RULE ID:321592)

Rule General Information
Release Date: 2018-10-09
Rule Name: Apache Pluto PortletV3AnnotatedDemo MultipartPortlet Arbitrary File Upload Vulnerability(CVE-2018-1306)
Severity:
CVE ID:
Rule Protection Details
Description: The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
Impact: The manipulation with an unknown input leads to a information disclosure vulnerability.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android
Reference: http://portals.apache.org/pluto/security.html
ExploitDB:45396
https://vuldb.com/?id.120031
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.