Information Disclosure Vulnerability in Fess Enterprise Search Server
CVE-2025-48382

1.2LOW

Key Information:

Vendor

Codelibs

Status
Vendor
CVE Published:
27 May 2025

What is CVE-2025-48382?

The Fess Enterprise Search Server contains a flaw in the createTempFile() method found in org.codelibs.fess.helper.SystemHelper. This method generates temporary files without setting appropriate restrictive permissions, potentially leading to information disclosure. Unauthorized local users could exploit this vulnerability to gain access to sensitive data stored in these temporary files, particularly in shared or multi-user environments. While isolated installations might see negligible impact, it's crucial for users to ensure that access to environments running Fess is limited to trusted individuals. The issue is resolved in version 14.19.2, and users are encouraged to upgrade to eliminate the risk. For an immediate workaround, enforcing strict local access controls is recommended.

Affected Version(s)

fess < 14.19.2

References

CVSS V4

Score:
1.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.