CVE-2022-24913

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:java-merge-sort_project:java-merge-sort:*:*:*:*:*:*:*:*

Information

Published : 2023-01-11 21:15

Updated : 2023-01-20 11:46


NVD link : CVE-2022-24913

Mitre link : CVE-2022-24913


JSON object : View

CWE
CWE-668

Exposure of Resource to Wrong Sphere

Advertisement

dedicated server usa

Products Affected

java-merge-sort_project

  • java-merge-sort