← לוח פגיעויות

CVE-2013-0248

בינונית 6.8

תיאור (מקור, אנגלית)

The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.

מדדים

CVSS 3.1
6.8 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CWE
CWE-264, CWE-59

מוצרים מושפעים

apache: commons fileupload

קישורים