Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28168

Опубликовано: 22 апр. 2021
Источник: redhat
CVSS3: 6.2

Описание

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

Отчет

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Important and Critical flaws.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6jersey-coreNot affected
Red Hat CodeReady Studio 12org.glassfish.jersey.core.jersey-commonWill not fix
Red Hat Fuse 7jersey-commonNot affected
Red Hat Integration Service Registryjersey-commonWill not fix
Red Hat JBoss Fuse 6jersey-commonNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hadoopNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-metering-hiveNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-metering-prestoNot affected
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1953024jersey: Local information disclosure via system temporary directory

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
nvd
почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
github
почти 5 лет назад

Local information disclosure via system temporary directory

CVSS3: 6.2
fstec
почти 5 лет назад

Уязвимость фреймворка Eclipse Jersey, связанная с созданием временных файлов с небезопасными разрешениями, позволяющая нарушителю раскрыть защищаемую информацию

6.2 Medium

CVSS3