Description
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
References
https://github.com/cowtowncoder/java-merge-sort/commit/450fdee70b5f181c2afc5d817f293efa1a543902
PatchThird Party Advisory
https://github.com/cowtowncoder/java-merge-sort/pull/21
PatchThird Party Advisory
https://security.snyk.io/vuln/SNYK-JAVA-COMFASTERXMLUTIL-3227926
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
5.5 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2023-01-12T05:15:11.477
1 year agoLast modified
2023-11-07T03:44:41.203
8 months ago