When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
2023-05-21T21:15:08.790
2025-01-31T16:15:29.970
Modified
CVSSv3.1: 4.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lightbend | akka_http | < 10.5.2 | Yes |
Operating System | linux | linux_kernel | - | No |