Intel

AIKIDO-2024-10490

akka-http_2.13 is vulnerable to Improper Access Control

Improper Access ControlCVE-2023-33251

55

Medium Risk

This Affects:

JAVAakka-http_2.13
3.0.0 - 10.5.1
Fixed in 10.5.2

TL;DR

In affected versions of Akka HTTP, the FileUploadDirectives.fileUploadAll directive creates temporary files with overly permissive access rights on Unix-like systems. These temporary files are readable by other users, which can lead to unauthorized access to sensitive data uploaded through the directive.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you are using the FileUploadDirectives.fileUploadAll function.

Background info

akka-http_2.13 is vulnerable to Improper Access Control in versions 3.0.0 - 10.5.1.

How to fix this

Upgrade the com.typesafe.akka:akka-http library to the patch version.

Background Info