Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.manydesigns/portofino-microservice-launcher
  4. ›
  5. CVE-2022-3952

CVE-2022-3952: Exposure of Resource to Wrong Sphere

November 11, 2022 (updated November 15, 2022)

A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLauncher.java. The manipulation leads to creation of temporary file in directory with insecure permissions. Upgrading to version 5.3.3 is able to address this issue. The name of the patch is 94653cb357806c9cf24d8d294e6afea33f8f0775. It is recommended to upgrade the affected component. The identifier VDB-213457 was assigned to this vulnerability.

References

  • github.com/ManyDesigns/Portofino/commit/94653cb357806c9cf24d8d294e6afea33f8f0775
  • github.com/ManyDesigns/Portofino/pull/580
  • github.com/ManyDesigns/Portofino/releases/tag/v5.3.3
  • nvd.nist.gov/vuln/detail/CVE-2022-3952

Code Behaviors & Features

Detect and mitigate CVE-2022-3952 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

Version 5.3.2

Fixed versions

  • 5.3.3

Solution

Upgrade to version 5.3.3 or above.

Impact 7.1 HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-668: Exposure of Resource to Wrong Sphere

Source file

maven/com.manydesigns/portofino-microservice-launcher/CVE-2022-3952.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:23 +0000.