PT-2013-2187 · Apache+1 · Apache Commons Fileupload+1
Published
2013-03-15
·
Updated
2024-05-27
·
CVE-2013-0248
CVSS v2.0
3.3
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Commons FileUpload versions 1.0 through 1.2.2
Description
The default configuration of
javax.servlet.context.tempdir in Apache Commons FileUpload uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.Recommendations
For Apache Commons FileUpload versions 1.0 through 1.2.2, consider changing the default configuration of
javax.servlet.context.tempdir to a directory that is not accessible by local users to prevent arbitrary file overwrites.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Commons Fileupload