CVE-2014-2966: Caucho Resin
Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
Affected products
- Caucho Resin: up to and including 4.0.39; version 4.0.36 only; version 4.0.37 only; version 4.0.38 only
Published 2014-07-26. Last modified 2026-06-17.