Описание
The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary directory before attempting to create it.
Ссылки
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.1 (исключая)
cpe:2.3:a:samtools:htsjdk:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00244
Низкий
7.3 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-668
Связанные уязвимости
CVSS3: 7.3
ubuntu
около 3 лет назад
The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary directory before attempting to create it.
CVSS3: 7.8
github
около 3 лет назад
HTSJDK is vulnerable to exposure of resource(s) to the wrong sphere
EPSS
Процентиль: 47%
0.00244
Низкий
7.3 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-668