{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acauchoresin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:caucho:resin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2017-20284"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Resin (documentation webapp)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","web-security"],"_cs_type":"threat","_cs_vendors":["Caucho"],"content_html":"\u003cp\u003eCaucho Resin contains a path traversal vulnerability within the resin-doc documentation web application. This flaw affects the jndi-appconfig tutorial servlet, where the inputFile request parameter is insufficiently sanitized. Remote, unauthenticated attackers can supply crafted directory traversal sequences (e.g., ../../) via this parameter to bypass intended file access restrictions. This allows for the unauthorized reading of sensitive files located outside the tutorial directory on the underlying host system. Exploitation of this vulnerability has been observed in the wild since December 10, 2021, as documented by the Shadowserver Foundation. Defenders should prioritize removing the documentation application in production environments or applying the necessary vendor patches to mitigate risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized disclosure of sensitive system files, configuration files, or credentials stored on the server. This can facilitate further attacks, such as credential theft or system compromise, depending on the files accessible to the service account running the Resin instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to web server access logs to detect directory traversal patterns in URI queries.\u003c/li\u003e\n\u003cli\u003eAudit production deployments and remove the 'resin-doc' documentation web application if it is not strictly required.\u003c/li\u003e\n\u003cli\u003eEnsure the Resin service is running with the principle of least privilege, limiting the files accessible by the process user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T22:08:12Z","date_published":"2026-09-18T22:08:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2017-20284/","summary":"A path traversal vulnerability (CVE-2017-20284) in the Caucho Resin documentation web application allows unauthenticated remote attackers to read arbitrary files via the inputFile parameter.","title":"Path Traversal Vulnerability in Caucho Resin Documentation Webapp","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2017-20284/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:caucho:resin:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}