CVE-2023-33251: Medium severity Lightbend Akka HTTP vulnerability
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33251?
CVE-2023-33251 is a vulnerability in Akka HTTP before version 10.5.2 that allows file uploads with weak file permissions.
How does CVE-2023-33251 affect Akka HTTP?
CVE-2023-33251 affects Akka HTTP before version 10.5.2, allowing file uploads with weak file permissions.
What is the severity of CVE-2023-33251?
The severity of CVE-2023-33251 is medium, with a severity value of 5.5.
How can I fix CVE-2023-33251?
To fix CVE-2023-33251, update your Akka HTTP installation to version 10.5.2 or later.
Where can I find more information about CVE-2023-33251?
You can find more information about CVE-2023-33251 at the following reference: [link](https://akka.io/security/akka-http-cve-2023-05-15.html)