Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-51127

Опубликовано: 04 нояб. 2024
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

A flaw was found in the createTempFile method of hornetq. Affected version of hornetq allows attackers to arbitrarily overwrite files or access sensitive information.

Меры по смягчению последствий

There is currently no known mitigation for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakorg.hornetq/hornetq-core-clientNot affected
Red Hat Fuse 7org.hornetq/hornetq-core-clientWill not fix
Red Hat JBoss Data Grid 7org.hornetq/hornetq-core-clientOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packorg.hornetq/hornetq-core-clientNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.eap-jboss-eapNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.eap-jboss-eap-xpNot affected
Red Hat Process Automation 7org.hornetq/hornetq-core-clientNot affected
Red Hat Single Sign-On 7org.hornetq/hornetq-core-clientNot affected
Important: Red Hat JBoss Enterprise Application Platform 7.4.21 security updateorg.hornetq/hornetq-core-clientFixedRHSA-2025:163518.02.2025
Red Hat JBoss Enterprise Application Platform 7FixedRHSA-2024:1153119.12.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2323697hornetq-core-client: Arbitrarily overwrite files or access sensitive information

EPSS

Процентиль: 73%
0.00781
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 года назад

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

CVSS3: 9.1
github
около 1 года назад

hornetq vulnerable to file overwrite, sensitive information disclosure

EPSS

Процентиль: 73%
0.00781
Низкий

7.1 High

CVSS3