Vulnerability record · CVE-2018-1306 · published 27 June 2018
CVE-2018-1306: Apache pluto information exposure vulnerability
Apache · Pluto
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
Description
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://portals.apache.org/pluto/security.html | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/45396/ | ExploitThird Party AdvisoryVDB Entry |
| http://portals.apache.org/pluto/security.html | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/45396/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-1306 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1306), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.