PT-2013-2187 · Apache+1 · Apache Commons Fileupload+1
CVE-2013-0248
·
Publicado
2013-03-15
·
Atualizado
2024-05-27
CVSS v2.0
3.3
Baixa
| Vetor | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Commons FileUpload versions 1.0 through 1.2.2
Description
The default configuration of
javax.servlet.context.tempdir in Apache Commons FileUpload uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.Recommendations
For Apache Commons FileUpload versions 1.0 through 1.2.2, consider changing the default configuration of
javax.servlet.context.tempdir to a directory that is not accessible by local users to prevent arbitrary file overwrites.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Apache Commons Fileupload