CVE-2022-45787
published 2023-01-06CVE-2022-45787: Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.27%
18.8th percentile
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions.
We recommend users to upgrade to MIME4j version 0.8.9 or later.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | james | < 0.8.9 | 0.8.9 |
| apache_software_foundation | apache_james_mime4j | <= 0.8.8 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Apache James MIME4J) — CVE-2022-45787
vendor_oracle·2023-07-15·CVSS 5.5
CVE-2022-45787 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Apache James MIME4J) — CVE-2022-45787
Oracle Oracle Communications Risk Matrix: Configuration (Apache James MIME4J) vulnerability
CVE: CVE-2022-45787
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2023 (JUL 2023)
Red Hat
apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
vendor_redhat·2023-01-06·CVSS 5.5
CVE-2022-45787 [MEDIUM] CWE-200 apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions.
We recommend users to upgrade to MIME4j version 0.8.9 or later.
A flaw was found in Apache James's Mime4j TempFileStorageProvider class, where it may set improper permissions when utilizing temporary files. This flaw allows a locally authorized attacker to access information outside their intended permissions.
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: org.keycloak-keycloak-parent (Migration Toolkit for Appli
OSV
Apache James MIME4J vulnerable to information disclosure to local users
osv·2023-01-06
CVE-2022-45787 [MEDIUM] Apache James MIME4J vulnerable to information disclosure to local users
Apache James MIME4J vulnerable to information disclosure to local users
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users to upgrade to MIME4j version 0.8.9 or later.
GHSA
Apache James MIME4J vulnerable to information disclosure to local users
ghsa·2023-01-06
CVE-2022-45787 [MEDIUM] CWE-200 Apache James MIME4J vulnerable to information disclosure to local users
Apache James MIME4J vulnerable to information disclosure to local users
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users to upgrade to MIME4j version 0.8.9 or later.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-06
Published