Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38795
HistoryJan 08, 2023 - 3:34 a.m.

Information Disclosure

2023-01-0803:34:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
vulnerable
information disclosure
temporary file configuration
createstorageoutputstream
tempfilestorageprovider
permissions
attacker
file content

0.0004 Low

EPSS

Percentile

5.1%

apache-mime4j-storage is vulnerable to Information Disclosure. The vulnerability exists due to insecure default temporary file configuration in the createStorageOutputStream function in TempFileStorageProvider.java, which creates a file with the permissions -rw-r--r--, allowing an attacker to read the content of the file.

0.0004 Low

EPSS

Percentile

5.1%