oss-sec mailing list archives

CVE-2026-28811: Apache JSPWiki: Error Handling Reveals Error Details


From: Juan Pablo Santos Rodríguez <juanpablo () apache org>
Date: Thu, 30 Jul 2026 14:14:06 +0200

Severity
Low

Vendor
The Apache Software Foundation

Versions Affected
Apache JSPWiki up to 2.12.3

Description
Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3.

Mitigation
Apache JSPWiki users should upgrade to 2.12.4 or later.

Credit
The issue was discovered by Cristian Borlovan from Ounce Labs


References
https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2026-28811
https://www.cve.org/CVERecord?id=CVE-2026-28811


Current thread: