CVE-2024-51127
Critical
CVE-2024-51127
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Exploit probability
0.7%
Published
November 4, 2024
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
4 explicit affected versions
114 explicit affected versions
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2024-51127
View original source
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Open Source Vulnerabilities
GHSA-r7mv-mv7m-pjw3
View original source
An issue in the `createTempFile` method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/51xxx/CVE-2024-51127.json
- https://github.com/JAckLosingHeart/CWE-378/blob/main/CVE-2024-51127.md
- https://nvd.nist.gov/vuln/detail/CVE-2024-51127
- http://hornetq.com
- https://github.com/darranl/hornetq
- https://github.com/hornetq/hornetq/blob/HornetQ_2_4_9_Final/hornetq-core-client/src/main/java/org/hornetq/core/client/impl/ClientConsumerImpl.java#L665C35-L665C49