Vulnerability Description
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users to upgrade to MIME4j version 0.8.9 or later.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | James | < 0.8.9 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/26s8p9stl1z261c4qw15bsq03tt7t0rjMailing ListVendor Advisory
- https://lists.apache.org/thread/26s8p9stl1z261c4qw15bsq03tt7t0rjMailing ListVendor Advisory
FAQ
What is CVE-2022-45787?
CVE-2022-45787 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 ...
How severe is CVE-2022-45787?
CVE-2022-45787 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45787?
Check the references section above for vendor advisories and patch information. Affected products include: Apache James.