Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-28168

Опубликовано: 22 апр. 2021
Источник: nvd
CVSS3: 6.2
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:eclipse:jersey:*:*:*:*:*:*:*:*
Версия от 2.28 (включая) до 2.34 (исключая)
cpe:2.3:a:eclipse:jersey:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.2 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00048
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-378
CWE-668

Связанные уязвимости

CVSS3: 6.2
ubuntu
почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
redhat
почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
github
почти 5 лет назад

Local information disclosure via system temporary directory

CVSS3: 6.2
fstec
почти 5 лет назад

Уязвимость фреймворка Eclipse Jersey, связанная с созданием временных файлов с небезопасными разрешениями, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 15%
0.00048
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-378
CWE-668