Skip to content

Latest commit

 

History

History
18 lines (16 loc) · 1.02 KB

CVE-2023-34442.md

File metadata and controls

18 lines (16 loc) · 1.02 KB
title date url draft type cve severity summary description mitigation credit affected fixed
Apache Camel Security Advisory - CVE-2023-34442
2023-07-07 11:15:42 +0200
/security/CVE-2023-34442.html
false
security-advisory
CVE-2023-34442
LOW
Temporary File Local Information Disclosure in camel-jira
The Camel-Jira FileConverter class is vulnerable to temporary file information disclosure. If sensitive information is written to this file, all other local users will be able to view the contents of that document.
Users should upgrade to 3.14.9, 3.18.8, 3.20.6 or 3.21.0 and for users on Camel 4.x update to 4.0.0-M1
This issue was discovered by Jonathan Leitschuh of the Open Source Security Foundation: Project Alpha-Omega
3.0.0 up to 3.14.8, and 3.18.0 up to 3.18.7, 3.20.0 up to 3.20.5 and 4.0.0-M1 up to 4.0.0-M3
3.14.9, 3.18.8, 3.20.6, 3.21.0 and 4.0.0-RC1

The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-19421 refers to the various commits that resovoled the issue, and have more details.