{"id":"GHSA-g88v-2j67-9rmx","summary":"Fess has Insecure Temporary File Permissions","details":"### Summary\nFess (an open-source Enterprise Search Server) creates temporary files without restrictive permissions, which may allow local attackers to read sensitive information from these temporary files.\n\n### Details\nThe `createTempFile()` method in `org.codelibs.fess.helper.SystemHelper` creates temporary files without explicitly setting restrictive permissions. This could lead to potential information disclosure, allowing unauthorized local users to access sensitive data contained in these files.\n\n### Impact\nThis issue primarily affects environments where Fess is deployed in a shared or multi-user context. Typical single-user or isolated deployments have minimal or negligible practical impact.\n\n### Workarounds\nEnsure local access to the environment running Fess is restricted to trusted users only.\n\n### References\n- [CVE-2022-24823: Netty temporary file permissions vulnerability](https://nvd.nist.gov/vuln/detail/CVE-2022-24823)","aliases":["CVE-2025-48382"],"modified":"2025-05-28T15:03:23.963197Z","published":"2025-05-27T18:00:48Z","database_specific":{"nvd_published_at":"2025-05-27T05:15:24Z","severity":"LOW","cwe_ids":["CWE-732"],"github_reviewed_at":"2025-05-27T18:00:48Z","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/codelibs/fess/security/advisories/GHSA-g88v-2j67-9rmx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48382"},{"type":"WEB","url":"https://github.com/codelibs/fess/commit/25b2009fea2a0f6ccd5aa8154aa54b536c08f6c4"},{"type":"PACKAGE","url":"https://github.com/codelibs/fess"}],"affected":[{"package":{"name":"org.codelibs.fess:fess","ecosystem":"Maven","purl":"pkg:maven/org.codelibs.fess/fess"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.19.2"}]}],"versions":["10.2.1","10.2.2","10.2.3","10.3.0","10.3.0-beta1","10.3.1","10.3.2","10.3.3","10.3.4","10.3.5","11.0.0","11.0.1","11.0.2","11.0.3","11.0.4","11.0.5","11.1.0","11.1.1","11.1.2","11.2.0","11.2.1","11.2.2","11.2.3","11.3.0","11.3.1","11.3.2","11.3.3","11.3.4","11.4.0","11.4.1","11.4.10","11.4.11","11.4.12","11.4.2","11.4.3","11.4.4","11.4.5","11.4.6","11.4.7","11.4.8","11.4.9","12.0.0","12.0.1","12.0.2","12.0.3","12.0.4","12.1.0","12.1.1","12.1.2","12.1.3","12.1.4","12.1.5","12.2.0","12.2.1","12.2.2","12.2.3","12.3.0","12.3.1","12.3.2","12.3.3","12.3.4","12.3.5","12.4.0","12.4.1","12.4.2","12.4.3","12.4.4","12.5.0","12.5.1","12.5.2","12.5.3","12.6.0","12.6.1","12.6.2","12.7.0","13.0.0","13.0.1","13.0.2","13.1.0","13.1.1","13.10.0","13.10.1","13.10.2","13.10.3","13.10.4","13.11.0","13.11.1","13.11.2","13.11.3","13.12.0","13.12.1","13.12.2","13.13.0","13.13.1","13.13.2","13.14.0","13.14.1","13.15.0","13.15.1","13.15.2","13.15.3","13.16.0","13.2.0","13.2.1","13.3.0","13.3.1","13.3.2","13.3.3","13.4.0","13.4.1","13.4.2","13.4.3","13.4.4","13.4.5","13.5.0","13.5.1","13.6.0","13.6.1","13.6.2","13.6.3","13.6.4","13.7.0","13.7.1","13.7.2","13.8.0","13.8.1","13.8.2","13.9.0","13.9.1","13.9.2","13.9.3","14.0.0","14.0.1","14.1.0","14.1.1","14.10.0","14.10.1","14.11.0","14.11.1","14.12.0","14.13.0","14.14.0","14.15.0","14.16.0","14.17.0","14.18.0","14.19.0","14.19.1","14.2.0","14.3.0","14.4.0","14.5.0","14.6.0","14.6.1","14.7.0","14.8.0","14.9.0","14.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-g88v-2j67-9rmx/GHSA-g88v-2j67-9rmx.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U"}]}