Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38076
HistoryNov 17, 2022 - 10:46 a.m.

Directory Hijacking

2022-11-1710:46:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
directory hijacking
file disclosure
createtempdir
warfilelauncher
sensitive information
software vulnerability

EPSS

0

Percentile

15.5%

com.manydesigns:portofino-microservice-launcher is vulnerable to directory hijacking. A local authenticated attacker is able to create temporary files inside unauthorized directories through createTempDir function of the file WarFileLauncher.java, resulting in disclosure of sensitive information and directory hijacking.

EPSS

0

Percentile

15.5%

Related for VERACODE:38076