{"id":"CVE-2019-17352","aliases":["GHSA-279p-pc38-xx4p"],"url":"https://o3.security/vulnerability/CVE-2019-17352","summary":"JFinal file validation vulnerability","details":"In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.","published":"2019-10-08T13:15:15.957Z","modified":"2026-07-08T20:04:09.985052Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"com.jfinal:jfinal","fixedVersion":"4.5"}],"fix":null,"references":[{"type":"REPORT","url":"https://gitee.com/jfinal/cos/commit/5eb23d6e384abaad19faa7600d14c9a2f525946a"},{"type":"REPORT","url":"https://gitee.com/jfinal/cos/commit/8d26eec61f0d072a68bf7393cf3a8544a1112130"},{"type":"EVIDENCE","url":"https://github.com/jfinal/jfinal/issues/171"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:04:09.985052Z"}}