Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpc7-wrgr-p3hh

Опубликовано: 19 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 4.4

Описание

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

EPSS

Процентиль: 4%
0.00018
Низкий

4.8 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-378

Связанные уязвимости

CVSS3: 4.4
redhat
около 1 месяца назад

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

CVSS3: 4.4
nvd
около 1 месяца назад

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

EPSS

Процентиль: 4%
0.00018
Низкий

4.8 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-378