Логотип exploitDog
bind:CVE-2021-21364
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21364

Количество 3

Количество 3

nvd логотип

CVE-2021-21364

почти 5 лет назад

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between all local users. When files/directories are created, the default `umask` settings for the process are respected. As a result, by default, most processes/apis will create files/directories with the permissions `-rw-r--r--` and `drwxr-xr-x` respectively, unless an API that explicitly sets safe file permissions is used. Because this vulnerability impacts generated code, the generated code will remain vulnerable until fixed manually! This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21363.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-21364

почти 5 лет назад

swagger-codegen is an open-source project which contains a template-dr ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hpv8-9rq5-hq7w

почти 5 лет назад

Generated Code Contains Local Information Disclosure Vulnerability

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21364

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between all local users. When files/directories are created, the default `umask` settings for the process are respected. As a result, by default, most processes/apis will create files/directories with the permissions `-rw-r--r--` and `drwxr-xr-x` respectively, unless an API that explicitly sets safe file permissions is used. Because this vulnerability impacts generated code, the generated code will remain vulnerable until fixed manually! This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21363.

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-21364

swagger-codegen is an open-source project which contains a template-dr ...

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-hpv8-9rq5-hq7w

Generated Code Contains Local Information Disclosure Vulnerability

CVSS3: 6.2
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу