Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54798

Опубликовано: 07 авг. 2025
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.

A flaw was found in tmp. The tmp module, used for creating temporary files and directories in Node.js, allows an arbitrary temporary file or directory write due to insufficient validation of the symbolic link parameter. This vulnerability allows a local attacker to provide a crafted symbolic link. This issue allows the creation of temporary files or directories at attacker-specified locations, potentially leading to unexpected behavior.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4io.cryostat-cryostatFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/log-file-metric-exporter-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Fix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2386976tmp: tmp Symbolic Link Write Vulnerability

EPSS

Процентиль: 3%
0.00017
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
22 дня назад

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.

CVSS3: 2.5
nvd
22 дня назад

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir parameter. This is fixed in version 0.2.4.

CVSS3: 2.5
debian
22 дня назад

tmp is a temporary file and directory creator for node.js. In versions ...

CVSS3: 2.5
github
22 дня назад

tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter

EPSS

Процентиль: 3%
0.00017
Низкий

2.5 Low

CVSS3