PT-2023-7199 · Apache · Apache Storm

Andrea Cosentino

·

Publicado

2023-11-23

·

Atualizado

2023-11-30

·

CVE-2023-43123

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Storm (affected versions not specified)
Description The issue is related to insufficient access control in the Apache Storm platform for distributed stream computing on UNIX-like systems. This can lead to information disclosure when writing to the temporary directory using APIs that do not explicitly set file or directory permissions. The method File.createTempFile creates a file with predefined name and default permissions -rw-r--r--, allowing other local users to read sensitive information written to this file. The impact is limited as the affected class is used only when ui.disable.spout.lag.monitoring is set to false, which is true by default, and the temporary file is deleted soon after creation.
Recommendations To resolve the issue, use Files.createTempFile instead of File.createTempFile to create temporary files with explicit permissions. As a temporary workaround, consider restricting access to the temporary directory until the issue is resolved. We recommend that all users upgrade to the latest version of Apache Storm.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08226
CVE-2023-43123
GHSA-85P4-Q357-72H9

Produtos afetados

Apache Storm