Information Disclosure Vulnerability in Fess Enterprise Search Server
CVE-2025-48382
What is CVE-2025-48382?
The Fess Enterprise Search Server contains a flaw in the createTempFile() method found in org.codelibs.fess.helper.SystemHelper. This method generates temporary files without setting appropriate restrictive permissions, potentially leading to information disclosure. Unauthorized local users could exploit this vulnerability to gain access to sensitive data stored in these temporary files, particularly in shared or multi-user environments. While isolated installations might see negligible impact, it's crucial for users to ensure that access to environments running Fess is limited to trusted individuals. The issue is resolved in version 14.19.2, and users are encouraged to upgrade to eliminate the risk. For an immediate workaround, enforcing strict local access controls is recommended.
Affected Version(s)
fess < 14.19.2
