Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoint. When a file is uploaded via this resource, the server will create a temporary file that will be deleted after the client sends a POST request to ‘/pmb/authorities/import/iimport_authorities’. This workflow is automated by the web client, however an attacker can trap and launch the second POST request to prevent the temporary file from being deleted.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Jan 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Jan 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoint. When a file is uploaded via this resource, the server will create a temporary file that will be deleted after the client sends a POST request to ‘/pmb/authorities/import/iimport_authorities’. This workflow is automated by the web client, however an attacker can trap and launch the second POST request to prevent the temporary file from being deleted. | |
Title | Incomplete Cleanup vulnerability in PMB platform | |
Weaknesses | CWE-459 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-01-16T13:09:14.896Z
Updated: 2025-01-16T14:09:54.540Z
Reserved: 2025-01-14T12:44:15.826Z
Link: CVE-2025-0473

Updated: 2025-01-16T14:09:50.980Z

Status : Received
Published: 2025-01-16T13:15:07.540
Modified: 2025-01-16T13:15:07.540
Link: CVE-2025-0473

No data.