{"id":"CVE-2013-0248","title":"The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.","summary":"The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","cwe":["CWE-264","CWE-59"],"vendor":"apache","product":"commons_fileupload","affected":["commons_fileupload = 1.0","commons_fileupload = 1.1","commons_fileupload = 1.1.1","commons_fileupload = 1.2","commons_fileupload = 1.2.1","commons_fileupload = 1.2.2"],"published":"2013-03-15","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:08.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2013-0248","references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html","label":"secalert@redhat.com"},{"url":"http://marc.info/?l=bugtraq&m=144050155601375&w=2","label":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","label":"secalert@redhat.com"},{"url":"http://www.osvdb.org/90906","label":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/58326","label":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/202107-39","label":"secalert@redhat.com"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://marc.info/?l=bugtraq&m=144050155601375&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.osvdb.org/90906","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/58326","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202107-39","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T18:27:32.562560Z"},"epss":0.0068,"epssPercentile":0.50786,"ingestedAt":"2026-10-07T19:44:15.633Z","slug":"CVE-2013-0248","body":"## Overview\n\nThe default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.\n\n## Affected\n\n- `commons_fileupload = 1.0`\n- `commons_fileupload = 1.1`\n- `commons_fileupload = 1.1.1`\n- `commons_fileupload = 1.2`\n- `commons_fileupload = 1.2.1`\n- `commons_fileupload = 1.2.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}