tree 973e37ef6d63442c4c4b689e9959fbe0e2a12a59
parent 38adfdbafd971cee15b548c54fcd9200eb3f3519
author Jonathan Leitschuh <jonathan.leitschuh@gmail.com> 1668867245 -0800
committer GitHub <noreply@github.com> 1668867245 +0000
gpgsig -----BEGIN PGP SIGNATURE-----
 
 wsBcBAABCAAQBQJjeOStCRBK7hj4Ov3rIwAABLwIAIjP5HiZt0qPgzWNgwtQzqYo
 KINvFs0q8adlmzsb4YN3ElpSS3QhyLHFdsJzax8mslD6e6PQV/5FwrVNgSipaJM9
 yqEEIbPS2dBGPeol1jTIgWZZHmKHj8S6bKWxhPZWQJyr04EKBokYy/7p/InWHvP1
 dd1yUiQoypw9U3bTD6Z2tUlzjfUOlWul1lwD7vDWudwKbLOKOfUkdAEAQ9NGWdGG
 BBs4vMmW0EUmSzxOyi4YVyeSL5moEk3ZeX5Uwug+DR+HvIAuRsNHaemRpV1L3xzg
 1pWCY+1Yn2Frcxf2gZUb5CoMdv6/Lyi4kNEwN7cX77ujVGiMAKfaKF82Ei28W68=
 =yMYc
 -----END PGP SIGNATURE-----
 

vuln-fix: Temporary File Information Disclosure (#1125)

This fixes temporary file information disclosure vulnerability due to the use
of the vulnerable `File.createTempFile()` method. The vulnerability is fixed by
using the `Files.createTempFile()` method which sets the correct posix permissions.

Weakness: CWE-377: Insecure Temporary File
Severity: Medium
CVSSS: 5.5
Detection: CodeQL & OpenRewrite (https://public.moderne.io/recipes/org.openrewrite.java.security.SecureTempFileCreation)

Reported-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>

Bug-tracker: https://github.com/JLLeitschuh/security-research/issues/18


Co-authored-by: Moderne <team@moderne.io>