PT-2024-34531 · Hornetq · Hornetq
Published
2024-11-04
·
Updated
2024-11-06
·
CVE-2024-51127
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
hornetq version 2.4.9
Description:
An issue in the
createTempFile method allows attackers to arbitrarily overwrite files or access sensitive information.Recommendations:
For hornetq version 2.4.9, consider disabling the
createTempFile method until a patch is available to prevent arbitrary file overwrites and sensitive information access.Exploit
Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hornetq