Versions of the package com.fasterxml.util:java-merge-sort
before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider()
function in StdTempFileProvider.java
, which uses the permissive File.createTempFile()
function, exposing temporary file contents.
{ "nvd_published_at": "2023-01-12T05:15:00Z", "github_reviewed_at": "2023-01-12T20:55:23Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-377", "CWE-668" ] }