Skip to main content

Threats Tagged 'cwe-378'

View all threats tagged with 'cwe-378'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-378

Threats Tagged 'cwe-378'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-4137 is a vulnerability in mlflow/mlflow prior to version 3.11.0 where temporary directories are created with insecure permissions, allowing local attackers to tamper with model artifacts. This can lead to arbitrary code execution when deserialized via cloudpickle.load(). The issue is especially critical in shared NFS environments like Databricks. It continues a previously partially fixed vulnerability class (CVE-2025-10279).

Join the discussion

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cache data.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.12.84. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/157795 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes Security Fix(es): None For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor.

Join the discussion

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Join the discussion

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

Join the discussion

CVE-2025-34352 is a high-severity local privilege escalation vulnerability in JumpCloud Remote Assist for Windows versions prior to 0.317.0. It arises from insecure creation and manipulation of temporary files by the uninstaller running with SYSTEM privileges. A low-privileged local attacker can exploit this by creating a user-writable %TEMP% subdirectory with weak permissions and leveraging symbolic links or mount points to redirect file operations. This can lead to arbitrary file writes or deletions in protected system locations, potentially causing denial of service or escalation to SYSTEM privileges. No user interaction is required, but local access with low privileges is necessary. The vulnerability affects Windows systems with JumpCloud Remote Assist installed and managed via the JumpCloud Agent lifecycle. The issue is fixed in version 0.317.

Join the discussion

The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. This vulnerability allows attackers on multi-user systems to steal proprietary models, poison cached embeddings, or conduct symlink attacks. The issue affects all Linux deployments where multiple users share the same system. The vulnerability is classified under CWE-379, CWE-377, and CWE-367, indicating insecure temporary file creation and potential race conditions.

Join the discussion

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cwe-378
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses