VYPR

RAP

by Eclipse

CVEs (1)

  • CVE-2023-4760Sep 21, 2023
    risk 0.00cvss epss 0.01

    In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.stripFileName(String name)…