← Vulnerability feed

Vulnerability record · CVE-2021-44138 · published 4 April 2022

CVE-2021-44138: Caucho resin path traversal vulnerability

Caucho · Resin

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

7.5 CVSS 3.1 High EPSS 12% · top 3.9% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/maybe-why-not/reponame/issues/2 ExploitThird Party Advisory
https://github.com/maybe-why-not/reponame/issues/2 ExploitThird Party Advisory

Track CVE-2021-44138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2012-2965Caucho resin improper input validation vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown i…EPSS 1.6%7.5CVE-2012-2966Caucho resin vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has …EPSS 1.6%7.5CVE-2012-2967Caucho resin vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which h…EPSS 1.6%6.4CVE-2012-2969Caucho resin permissions and access controls vulnerabilityCaucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created fil…EPSS 3.5%5.0CVE-2014-2966Caucho resin improper input validation vulnerabilityThe ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended…EPSS 1.7%5.0CVE-2012-2968Caucho resin path traversal vulnerabilityDirectory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary dire…EPSS 3.5%5.0CVE-2004-0281Caucho resin vulnerabilityCaucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP req…EPSS 4.2%4.3CVE-2010-2032Caucho resin cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possi…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2021-44138), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.