CVE-2021-45967
18.03.2022, 05:15
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
Vendor | Product | Version |
---|---|---|
pascom | cloud_phone_system | 𝑥 ≤ 7.19 |
igniterealtime | openfire | 𝑥 < 4.5.0 |
igniterealtime | openfire | 4.5.0 |
𝑥
= Vulnerable software versions
References