U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited security flaws catalog
What happened
Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : CVE-2015-3306 (CVSS score of 10.0) – An access control flaw in ProFTPD that could let remote attackers read or modify arbitrary files by abusing the SITE CPFR and SITE CPTO commands. CVE-2021-3199 (CVSS score of 9.8) – A path traversal flaw in ONLYOFFICE Docs when JSON Web Token (JWT) is enabled.
CVE-2023-22894 (CVSS score of 7.2) – A vulnerability in Strapi that exposes sensitive information stored in cleartext. CVE-2016-3081 (CVSS score of 8.1) – A command injection flaw in Apache Struts that could allow remote attackers to run arbitrary code through method: prefixes when Dynamic Method Invocation is enabled. CVE-2015-5477 (CVSS score of 7.5) – A reachable assertion vulnerability in ISC BIND that could be triggered by remote TKEY queries, potentially causing a denial-of-service condition.
Sources & evidence
- Security Affairs Reporting source
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog ↗
https://securityaffairs.com/200734/security/u-s-cisa-adds-proftpd-onlyoffice-docs-strapi-apache-struts-and-isc-bind-flaws-to-its-known-exploited-vulnerabilities-catalog.html