Описание
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
Ссылки
- MitigationVendor Advisory
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.5.2 (исключая)
Одновременно
cpe:2.3:a:lightbend:akka_http:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.00036
Низкий
4.7 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
NVD-CWE-Other
CWE-732
Связанные уязвимости
CVSS3: 4.7
github
больше 2 лет назад
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
EPSS
Процентиль: 10%
0.00036
Низкий
4.7 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
NVD-CWE-Other
CWE-732