Exposure of Resource to Wrong Sphere Affecting cassandra-reaper package, versions <4.0.1-r1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.91% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-CASSANDRAREAPER-15376271
  • published4 Mar 2026
  • disclosed22 Apr 2021

Introduced: 22 Apr 2021

CVE-2021-28168  (opens in a new tab)
CWE-668  (opens in a new tab)

How to fix?

Upgrade Wolfi cassandra-reaper to version 4.0.1-r1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cassandra-reaper package and not the cassandra-reaper package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.

References

CVSS Base Scores

version 3.1