keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Keycloak-httpd-client-install | Keycloak-httpd-client-install_project | * | 0.8 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | keycloak-httpd-client-install-0:0.8-1.el7 | * |