CVE-2017-5869: Nuxeo

High severity, CVSS 8.8. EPSS: 34.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.

Affected products

  • Nuxeo Nuxeo: version 6.0 only; version 7.1 only; version 7.2 only; version 7.3 only

Published 2017-03-24. Last modified 2026-06-17.