Описание
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.0 (исключая)
cpe:2.3:a:java-merge-sort_project:java-merge-sort:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00068
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-377
CWE-668
CWE-668
Связанные уязвимости
CVSS3: 5.5
github
около 3 лет назад
Java Merge-sort Insecure Temporary File vulnerability
EPSS
Процентиль: 21%
0.00068
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-377
CWE-668
CWE-668