Skip to content

Commit 450fdee

Browse files
vuln-fix: Temporary File Information Disclosure
This fixes temporary file information disclosure vulnerability due to the use of the vulnerable `File.createTempFile()` method. The vulnerability is fixed by using the `Files.createTempFile()` method which sets the correct posix permissions. Weakness: CWE-377: Insecure Temporary File Severity: Medium CVSSS: 5.5 Detection: CodeQL & OpenRewrite (https://public.moderne.io/recipes/org.openrewrite.java.security.SecureTempFileCreation) Reported-by: Jonathan Leitschuh <[email protected]> Signed-off-by: Jonathan Leitschuh <[email protected]> Bug-tracker: JLLeitschuh/security-research#18 Co-authored-by: Moderne <[email protected]>
1 parent 83b29a8 commit 450fdee

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

Diff for: src/main/java/com/fasterxml/sort/std/StdTempFileProvider.java

+2-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
package com.fasterxml.sort.std;
22

33
import java.io.*;
4+
import java.nio.file.Files;
45

56
import com.fasterxml.sort.TempFileProvider;
67

@@ -35,7 +36,7 @@ public StdTempFileProvider(String prefix, String suffix) {
3536
@Override
3637
public File provide() throws IOException
3738
{
38-
File f = File.createTempFile(_prefix, _suffix);
39+
File f = Files.createTempFile(_prefix, _suffix).toFile();
3940
f.deleteOnExit();
4041
return f;
4142
}

0 commit comments

Comments
 (0)