Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.
| Software | From | Fixed in |
|---|---|---|
| nuxeo / nuxeo | 7.3 | 7.3.x |
| nuxeo / nuxeo | 6.0 | 6.0.x |
| nuxeo / nuxeo | 7.2 | 7.2.x |
| nuxeo / nuxeo | 7.1 | 7.1.x |