WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited security flaws catalog

Small padlock on a network cable at a patch panelAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : CVE-2015-3306 (CVSS score of 10.0) – An access control flaw in ProFTPD that could let remote attackers read or modify arbitrary files by abusing the SITE CPFR and SITE CPTO commands. CVE-2021-3199 (CVSS score of 9.8) – A path traversal flaw in ONLYOFFICE Docs when JSON Web Token (JWT) is enabled.

CVE-2023-22894 (CVSS score of 7.2) – A vulnerability in Strapi that exposes sensitive information stored in cleartext. CVE-2016-3081 (CVSS score of 8.1) – A command injection flaw in Apache Struts that could allow remote attackers to run arbitrary code through method: prefixes when Dynamic Method Invocation is enabled. CVE-2015-5477 (CVSS score of 7.5) – A reachable assertion vulnerability in ISC BIND that could be triggered by remote TKEY queries, potentially causing a denial-of-service condition.

Sources & evidence