Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-34442

Опубликовано: 07 июл. 2023
Источник: redhat
CVSS3: 3.3

Описание

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3. Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1

A flaw was found in the camel-jira package. The package was creating a file directly instead of using Files.createTempFile in FileConverter, which could lead to the unexpected creation of a file in a vulnerable directory, giving access to unauthorized actors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3camel-jiraNot affected
Red Hat Fuse 7camel-jiraOut of support scope
Red Hat Integration Camel K 1camel-jiraAffected
Red Hat Integration Camel Quarkus 2camel-jiraFix deferred
Red Hat JBoss Fuse 6camel-jiraOut of support scope
Red Hat JBoss Fuse Service Works 6camel-jiraOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2227782camel-jira: Temporary file information disclosure in Camel-Jira

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
больше 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This issue affects Apache Camel: from 3.X through <=3.14.8, from 3.18.X through <=3.18.7, from 3.20.X through <= 3.20.5, from 4.X through <= 4.0.0-M3. Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1

CVSS3: 3.3
github
больше 2 лет назад

Apache Camel information exposure vulnerability

CVSS3: 3.3
fstec
больше 2 лет назад

Уязвимость шаблонов java-фреймворка Apache Camel, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

3.3 Low

CVSS3