Description
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAhornetq vulnerable to file overwrite, sensitive information disclosure↗2024-11-04 ▶ OSVhornetq vulnerable to file overwrite, sensitive information disclosure↗2024-11-04 ▶ CVEListCVE-2024-51127: An issue in the createTempFile method of hornetq v2↗2024-11-04 ▶ 📋Vendor Advisories
1Red Hathornetq-core-client: Arbitrarily overwrite files or access sensitive information↗2024-11-04 ▶