Description
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Automated Content for Real Estate Multiple Unspecified Vulnerabilities (5.4.2)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2021-21604)
Drupal Core 8.4.x Remote Code Execution (8.4.0 - 8.4.7)
WordPress Plugin WooCommerce BuddyPress Integration Security Bypass (3.2.5)