CVE-2024-51127
published 2024-11-04CVE-2024-51127: An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
PriorityP432high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.67%
47.8th percentile
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | hornetq | <= 2.4.9 | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
hornetq vulnerable to file overwrite, sensitive information disclosure
ghsa·2024-11-04
CVE-2024-51127 [HIGH] CWE-200 hornetq vulnerable to file overwrite, sensitive information disclosure
hornetq vulnerable to file overwrite, sensitive information disclosure
An issue in the `createTempFile` method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
OSV
hornetq vulnerable to file overwrite, sensitive information disclosure
osv·2024-11-04
CVE-2024-51127 [HIGH] hornetq vulnerable to file overwrite, sensitive information disclosure
hornetq vulnerable to file overwrite, sensitive information disclosure
An issue in the `createTempFile` method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Red Hat
hornetq-core-client: Arbitrarily overwrite files or access sensitive information
vendor_redhat·2024-11-04·CVSS 7.1
CVE-2024-51127 [HIGH] CWE-22 hornetq-core-client: Arbitrarily overwrite files or access sensitive information
hornetq-core-client: Arbitrarily overwrite files or access sensitive information
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
A flaw was found in the createTempFile method of hornetq. Affected version of hornetq allows attackers to arbitrarily overwrite files or access sensitive information.
Mitigation: There is currently no known mitigation for this vulnerability.
Package: org.hornetq/hornetq-core-client (Red Hat Build of Keycloak) - Not affected
Package: org.hornetq/hornetq-core-client (Red Hat Fuse 7) - Will not fix
Package: org.hornetq/hornetq-core-client (Red Hat JBoss Data Grid 7) - Out of support scope
Package: org.hornetq/hornetq-core-client (Red Hat JBoss Enterprise Application Platf
No detection rules found.
No public exploits indexed.
2024-11-04
Published