Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40984
HistoryJun 22, 2023 - 7:59 a.m.

Information Disclosure

2023-06-2207:59:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
information disclosure
fileutil.java
temporary file
default permissions
system security

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0

Percentile

9.0%

Hutool Core is vulnerable to Information Disclosure. The vulnerability exists in createTempFile function at FileUtil.java because the temporary file has insecure default permissions which allows an attacker to read the file on the system

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0

Percentile

9.0%