High severity7.5NVD Advisory· Published Mar 28, 2019· Updated Jun 17, 2026
CVE-2019-0225
CVE-2019-0225
Description
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.jspwiki:jspwiki-warMaven | >= 2.9.0, < 2.11.0.M3 | 2.11.0.M3 |
Affected products
9cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*range: >=2.9.0,<2.11.0
- cpe:2.3:a:apache:jspwiki:2.11.0:-:*:*:*:*:*:*
- cpe:2.3:a:apache:jspwiki:2.11.0:milestone1-rc1:*:*:*:*:*:*
- cpe:2.3:a:apache:jspwiki:2.11.0:milestone1-rc2:*:*:*:*:*:*
- cpe:2.3:a:apache:jspwiki:2.11.0:milestone1-rc3:*:*:*:*:*:*
- cpe:2.3:a:apache:jspwiki:2.11.0:milestone2-rc1:*:*:*:*:*:*
- cpe:2.3:a:apache:jspwiki:2.11.0:milestone2:*:*:*:*:*:*
- Apache/Apache JSPWikiv5Range: Apache JSPWiki 2.9.0 to 2.11.0.M2
Patches
Vulnerability mechanics
References
15- www.openwall.com/lists/oss-security/2019/03/26/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/107627nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-pffw-p2q5-w6vhghsaADVISORY
- jspwiki-wiki.apache.org/Wiki.jspnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-0225ghsaADVISORY
- lists.apache.org/thread.html/03ddbcb1d6322e04734e65805a147a32bcfdb71b8fc5821fb046ba8d@%3Cannounce.apache.org%3EghsaWEB
- lists.apache.org/thread.html/4f19fdbd8b9c4caf6137a459d723f4ec60379b033ed69277eb4e0af9@%3Cuser.jspwiki.apache.org%3EghsaWEB
- lists.apache.org/thread.html/6251c06cb11e0b495066be73856592dbd7ed712487ef283d10972831@%3Cdev.jspwiki.apache.org%3EghsaWEB
- lists.apache.org/thread.html/aac253cfc33c0429b528e2fcbe82d3a42d742083c528f58d192dfd16@%3Ccommits.jspwiki.apache.org%3EghsaWEB
- lists.apache.org/thread.html/e42d6e93384d4a33e939989cd00ea2a06ccf1e7bb1e6bdd3bf5187c1@%3Ccommits.jspwiki.apache.org%3EghsaWEB
- lists.apache.org/thread.html/03ddbcb1d6322e04734e65805a147a32bcfdb71b8fc5821fb046ba8d%40%3Cannounce.apache.org%3Envd
- lists.apache.org/thread.html/4f19fdbd8b9c4caf6137a459d723f4ec60379b033ed69277eb4e0af9%40%3Cuser.jspwiki.apache.org%3Envd
- lists.apache.org/thread.html/6251c06cb11e0b495066be73856592dbd7ed712487ef283d10972831%40%3Cdev.jspwiki.apache.org%3Envd
- lists.apache.org/thread.html/aac253cfc33c0429b528e2fcbe82d3a42d742083c528f58d192dfd16%40%3Ccommits.jspwiki.apache.org%3Envd
- lists.apache.org/thread.html/e42d6e93384d4a33e939989cd00ea2a06ccf1e7bb1e6bdd3bf5187c1%40%3Ccommits.jspwiki.apache.org%3Envd
News mentions
0No linked articles in our index yet.