First published: Tue Jun 13 2023(Updated: )
Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the `File.createTempFile()` function at `/core/io/FileUtil.java`.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hutool Hutool | <=5.8.17 | |
maven/cn.hutool:hutool-core | <5.8.19 | 5.8.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-33695.
The severity of CVE-2023-33695 is high with a CVSS score of 7.1.
The vulnerability in Hutool v5.8.17 and below is an information disclosure vulnerability, which can be exploited via the File.createTempFile() function in the FileUtil.java file.
Versions up to and including Hutool v5.8.17 are affected by CVE-2023-33695.
To fix the information disclosure vulnerability in Hutool, update to a version higher than 5.8.17 that includes the necessary security patches.