CVE-2013-0248
Publication date 15 March 2013
Last updated 8 October 2026
Ubuntu priority
Cvss 3 Severity Score
Description
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libcommons-fileupload-java | ||
Notes
mdeslaur
version 1.3 added documentation notes that a directory should be specified when using the API. this isn't worth fixing in stable releases
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.8 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L