CVE-2013-0248
Executive Summary
Apache Commons FileUpload 1.0‑1.2.2 defaults to using /tmp for uploaded files. This allows local users to exploit an unspecified symlink attack to overwrite arbitrary files on the system, potentially leading to data corruption or privilege escalation. The vulnerability is not listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 6.8 (MEDIUM) - Published: 2013-03-15T20:55:10.553 - Last Modified: 2026-10-07T19:17:08.970
Original Description: The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
"We must embrace pain and burn it as fuel for our journey."
— Kenji Miyazawa