[MAVEN:GHSA-QXXC-7MQ4-MF79] Java Merge-sort Insecure Temporary File vulnerability

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.

Package Affected Version
pkg:maven/com.fasterxml.util/java-merge-sort < 1.1.0
Package Fixed Version
pkg:maven/com.fasterxml.util/java-merge-sort = 1.1.0
ID
MAVEN:GHSA-QXXC-7MQ4-MF79
Severity
moderate
URL
https://github.com/advisories/GHSA-qxxc-7mq4-mf79
Published
2023-01-12T06:30:24
(20 months ago)
Modified
2023-01-20T22:03:36
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.fasterxml.util/java-merge-sort com.fasterxml.util java-merge-sort < 1.1.0
Fixed pkg:maven/com.fasterxml.util/java-merge-sort com.fasterxml.util java-merge-sort = 1.1.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...