CVE Vulnerabilities

CVE-2022-24913

Insecure Temporary File

Published: Jan 12, 2023 | Modified: Apr 08, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.

Weakness

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Affected Software

NameVendorStart VersionEnd Version
Java-merge-sortJava-merge-sort_project*1.1.0 (excluding)

References