Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45787

Опубликовано: 06 янв. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users to upgrade to MIME4j version 0.8.9 or later.

A flaw was found in Apache James's Mime4j TempFileStorageProvider class, where it may set improper permissions when utilizing temporary files. This flaw allows a locally authorized attacker to access information outside their intended permissions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Migration Toolkit for Applications 6org.keycloak-keycloak-parentNot affected
Migration Toolkit for Runtimesorg.keycloak-keycloak-parentNot affected
Red Hat build of Apache Camel for Spring Boot 3apache-james-mime4jFix deferred
Red Hat Data Grid 8apache-james-mime4jNot affected
Red Hat Decision Manager 7apache-james-mime4jOut of support scope
Red Hat Fuse 7apache-james-mime4jOut of support scope
Red Hat Integration Camel K 1apache-james-mime4jFix deferred
Red Hat Integration Camel Quarkus 1apache-james-mime4jWill not fix
Red Hat JBoss Data Grid 7apache-james-mime4jOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2158916apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider

EPSS

Процентиль: 1%
0.00008
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 3 лет назад

Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users to upgrade to MIME4j version 0.8.9 or later.

CVSS3: 5.5
github
около 3 лет назад

Apache James MIME4J vulnerable to information disclosure to local users

EPSS

Процентиль: 1%
0.00008
Низкий

5.5 Medium

CVSS3