5.5
CVSSv3

CVE-2023-33251

Published: 21/05/2023 Updated: 30/05/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

When Akka HTTP prior to 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.

Vulnerable Product Search on Vulmon Subscribe to Product

lightbend akka_http