Логотип exploitDog
bind:CVE-2023-43123
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-43123

Количество 3

Количество 3

nvd логотип

CVE-2023-43123

около 2 лет назад

On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method File.createTempFile on unix-like systems creates a file with predefined name (so easily identifiable) and by default will create this file with the permissions -rw-r--r--. Thus, if sensitive information is written to this file, other local users can read this information. File.createTempFile(String, String) will create a temporary file in the system temporary directory if the 'java.io.tmpdir' system property is not explicitly set. This affects the class  https://github.com/apache/storm/blob/master/storm-core/src/jvm/org/apache/storm/utils/TopologySpoutLag.java#L99  and was introduced by  https://issues.apache.org/jira/browse/STORM-3123 In practice, this has a very limited impact as this class is

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-85p4-q357-72h9

около 2 лет назад

Apache Storm Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2023-08226

около 2 лет назад

Уязвимость программной платформы для распределенных потоковых вычислений Apache Storm в UNIX-подобных операционных системах, связанная с недостатками контроля доступа, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-43123

On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method File.createTempFile on unix-like systems creates a file with predefined name (so easily identifiable) and by default will create this file with the permissions -rw-r--r--. Thus, if sensitive information is written to this file, other local users can read this information. File.createTempFile(String, String) will create a temporary file in the system temporary directory if the 'java.io.tmpdir' system property is not explicitly set. This affects the class  https://github.com/apache/storm/blob/master/storm-core/src/jvm/org/apache/storm/utils/TopologySpoutLag.java#L99  and was introduced by  https://issues.apache.org/jira/browse/STORM-3123 In practice, this has a very limited impact as this class is

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-85p4-q357-72h9

Apache Storm Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files

CVSS3: 5.5
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-08226

Уязвимость программной платформы для распределенных потоковых вычислений Apache Storm в UNIX-подобных операционных системах, связанная с недостатками контроля доступа, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 3.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу