CVE-2013-4373
published 2013-10-24CVE-2013-4373: The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by…
PriorityP411low3.2CVSS 2.0
AVLACLAuSCNIPAP
EPSS
0.30%
22.4th percentile
The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | — | — |
CVSS provenance
nvdv2.03.2LOWAV:L/AC:L/Au:S/C:N/I:P/A:P
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Drift: Malicious drift file import due to insecure temporary file usage
vendor_redhat·2013-10-21·CVSS 3.2
CVE-2013-4373 [LOW] CWE-377 Drift: Malicious drift file import due to insecure temporary file usage
Drift: Malicious drift file import due to insecure temporary file usage
The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
Package: jpadrift (Red Hat JBoss Operations Network 3.1) - Affected
GHSA
GHSA-jqgv-v967-8r8h: The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3
ghsa_unreviewed·2022-05-17
CVE-2013-4373 [LOW] CWE-20 GHSA-jqgv-v967-8r8h: The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3
The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-1448.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1011824https://exchange.xforce.ibmcloud.com/vulnerabilities/88179http://rhn.redhat.com/errata/RHSA-2013-1448.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1011824https://exchange.xforce.ibmcloud.com/vulnerabilities/88179
2013-10-24
Published