CVE-2025-64319: Medium severity Salesforce Mulesoft Anypoint Code Builder vulnerability
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64319?
The severity of CVE-2025-64319 is classified as a high risk due to its potential for unauthorized manipulation of writable configuration files.
How do I fix CVE-2025-64319?
To fix CVE-2025-64319, users should upgrade to Salesforce Mulesoft Anypoint Code Builder version 1.11.6 or later.
What impact does CVE-2025-64319 have on Mulesoft Anypoint Code Builder?
CVE-2025-64319 allows attackers to manipulate critical writable configuration files, potentially leading to unauthorized access or configuration changes.
Who is affected by CVE-2025-64319?
Anyone using Salesforce Mulesoft Anypoint Code Builder versions prior to 1.11.6 is affected by CVE-2025-64319.
Is there a workaround for CVE-2025-64319 until a fix is applied?
There are no official workarounds for CVE-2025-64319; immediate upgrading to version 1.11.6 is recommended.