Описание
Incorrect Default Permissions in Apache Commons FileUpload
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-0248
- https://security.gentoo.org/glsa/202107-39
- http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html
- http://marc.info/?l=bugtraq&m=144050155601375&w=2
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.osvdb.org/90906
Пакеты
commons-fileupload:commons-fileupload
>= 1.0, < 1.2.2
1.2.2
Связанные уязвимости
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
The default configuration of javax.servlet.context.tempdir in Apache C ...