[
https://issues.apache.org/jira/browse/KNOX-2590?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Tamás Hanicz resolved KNOX-2590.
--------------------------------
Resolution: Duplicate
> Upgrade netty-handler to netty-codec-http:4.1.59.Final
> ------------------------------------------------------
>
> Key: KNOX-2590
> URL: https://issues.apache.org/jira/browse/KNOX-2590
> Project: Apache Knox
> Issue Type: Improvement
> Reporter: Akshay Kotecha Jain
> Priority: Trivial
>
> Netty is an open-source, asynchronous event-driven network application
> framework for the rapid development of maintainable high-performance protocol
> servers & clients. In Netty before version 4.1.59.Final there is a
> vulnerability on Unix-like systems involving an insecure temp file. When
> netty's multipart decoders are used local information disclosure can occur
> via the local system temporary directory if temporary storing uploads on the
> disk are enabled. On Unix-like systems, the temporary directory is shared
> between all users. As such, writing to this directory using APIs that do not
> explicitly set the file/directory permissions can lead to information
> disclosure. Of note, this does not impact modern MacOS Operating Systems. The
> method "File.createTempFile" on Unix-like systems creates a random file, but,
> by default will create this file with the permissions "-rw-r--r--". Thus, if
> sensitive information is written to this file, other local users can read
> this information. This is the case in netty's "AbstractDiskHttpData" is
> vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one
> may specify your own "java.io.tmpdir" when you start the JVM or use
> "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something
> that is only readable by the current user.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)