Uploaded image for project: 'Migration Toolkit for Applications'
  1. Migration Toolkit for Applications
  2. MTA-75

CVE org.keycloak-keycloak-parent: apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider [mta-6]

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False

      Security Tracking Issue

      Do not make this issue public.

      Impact: Moderate
      Reported Date: 06-Jan-2023
      PM Fix/Wontfix Decision By: 08-Feb-2023
      Resolve Bug By: 05-Jul-2023

      In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this bug.

      Please review this tracker and its impact on your product or service, as soon as possible. The trackers are filed WITHOUT in-depth analysis as the vulnerability has a Low or Moderate severity impact on this product or service. For more details, please refer to following confluence page - https://docs.engineering.redhat.com/x/3e_3EQ

      Please see the Security Errata Policy for further details: https://docs.engineering.redhat.com/x/9kKpDw

      Flaw:


      apache-james-mime4j: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
      https://bugzilla.redhat.com/show_bug.cgi?id=2158916

      Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users to upgrade to MIME4j version 0.8.9 or later.

      https://lists.apache.org/thread/26s8p9stl1z261c4qw15bsq03tt7t0rj

            jortel Jeff Ortel
            ahanwate1@redhat.com Avinash Hanwate
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: