CVE-2021-28168
jersey: Local information disclosure via system temporary directory
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.
Eclipse Jersey versiones 2.28 hasta 2.33 y Eclipse Jersey versiones 3.0.0 hasta 3.0.1, contienen una vulnerabilidad de divulgación de información local. Esto es debido al uso de la función File.createTempFile que crea un archivo dentro del directorio temporal del sistema con los permisos:-rw-r--r--. Por lo tanto, el contenido de este archivo es visible para todos los demás usuarios localmente en el sistema. Como tal, si el contenido escrito es sensible a la seguridad, puede ser revelado a otros usuarios locales
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-12 CVE Reserved
- 2021-04-22 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-378: Creation of Temporary File With Insecure Permissions
- CWE-379: Creation of Temporary File in Directory with Insecure Permissions
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (21)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/eclipse-ee4j/jersey/pull/4712 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-28168 | 2022-03-23 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1953024 | 2022-03-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Jersey Search vendor "Eclipse" for product "Jersey" | >= 2.28 < 2.34 Search vendor "Eclipse" for product "Jersey" and version " >= 2.28 < 2.34" | - |
Affected
| ||||||
Eclipse Search vendor "Eclipse" | Jersey Search vendor "Eclipse" for product "Jersey" | >= 3.0.0 < 3.0.2 Search vendor "Eclipse" for product "Jersey" and version " >= 3.0.0 < 3.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Policy Search vendor "Oracle" for product "Communications Cloud Native Core Policy" | 1.15.0 Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.15.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Unified Data Repository Search vendor "Oracle" for product "Communications Cloud Native Core Unified Data Repository" | 1.15.0 Search vendor "Oracle" for product "Communications Cloud Native Core Unified Data Repository" and version "1.15.0" | - |
Affected
|