Количество 2
Количество 2

CVE-2021-21428
Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system. The issue has been patched with `Files.createTempFile` and released in the v5.1.0 stable version.
GHSA-23x4-m842-fmwf
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2021-21428 Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system. The issue has been patched with `Files.createTempFile` and released in the v5.1.0 stable version. | CVSS3: 9.3 | 0% Низкий | около 4 лет назад |
GHSA-23x4-m842-fmwf Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator | CVSS3: 9.3 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу