PT-2023-24451 · Hutool · Hutool

Alex111998

·

Publicado

2023-06-13

·

Atualizado

2023-06-21

·

CVE-2023-33695

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hutool versions 5.8.17 and below
Description The issue is related to an information disclosure vulnerability. It is associated with the File.createTempFile() function located at /core/io/FileUtil.java.
Recommendations For Hutool versions 5.8.17 and below, consider updating to a version above 5.8.17 to resolve the issue. As a temporary workaround, consider restricting access to the FileUtil.java file to minimize the risk of exploitation.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33695
GHSA-7MCW-XMX3-7P8M

Produtos afetados

Hutool