Логотип exploitDog
bind:CVE-2021-28168
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-28168

Количество 5

Количество 5

ubuntu логотип

CVE-2021-28168

почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2021-28168

почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
EPSS: Низкий
nvd логотип

CVE-2021-28168

почти 5 лет назад

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-c43q-5hpj-4crv

почти 5 лет назад

Local information disclosure via system temporary directory

CVSS3: 6.2
EPSS: Низкий
fstec логотип

BDU:2023-05326

почти 5 лет назад

Уязвимость фреймворка Eclipse Jersey, связанная с созданием временных файлов с небезопасными разрешениями, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-28168

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-28168

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-28168

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

CVSS3: 6.2
0%
Низкий
почти 5 лет назад
github логотип
GHSA-c43q-5hpj-4crv

Local information disclosure via system temporary directory

CVSS3: 6.2
0%
Низкий
почти 5 лет назад
fstec логотип
BDU:2023-05326

Уязвимость фреймворка Eclipse Jersey, связанная с созданием временных файлов с небезопасными разрешениями, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.2
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу