PT-2024-34531 · Hornetq · Hornetq
CVE-2024-51127
·
Published
2024-11-04
·
Updated
2024-11-06
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
hornetq version 2.4.9
Description:
An issue in the
createTempFile method allows attackers to arbitrarily overwrite files or access sensitive information.Recommendations:
For hornetq version 2.4.9, consider disabling the
createTempFile method until a patch is available to prevent arbitrary file overwrites and sensitive information access.Exploit
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hornetq