Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Fix Temporary File Information Disclosure Vulnerability #254

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Commits on Nov 19, 2022

  1. vuln-fix: Temporary File Information Disclosure

    This fixes temporary file information disclosure vulnerability due to the use
    of the vulnerable `File.createTempFile()` method. The vulnerability is fixed by
    using the `Files.createTempFile()` method which sets the correct posix permissions.
    
    Weakness: CWE-377: Insecure Temporary File
    Severity: Medium
    CVSSS: 5.5
    Detection: CodeQL & OpenRewrite (https://public.moderne.io/recipes/org.openrewrite.java.security.SecureTempFileCreation)
    
    Reported-by: Jonathan Leitschuh <[email protected]>
    Signed-off-by: Jonathan Leitschuh <[email protected]>
    
    Bug-tracker: JLLeitschuh/security-research#18
    
    
    Co-authored-by: Moderne <[email protected]>
    JLLeitschuh and TeamModerne committed Nov 19, 2022
    Configuration menu
    Copy the full SHA
    9410a82 View commit details
    Browse the repository at this point in the history