CVE-2012-2966: Caucho Resin

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote attack vectors.

Affected products

  • Caucho Resin: up to and including 4.0.28; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …

Published 2012-08-12. Last modified 2026-06-16.