Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Fix Temporary Directory Hijacking or Information Disclosure Vulnerability #2406

Commits on Jul 27, 2022

  1. vuln-fix: Temporary Directory Hijacking or Information Disclosure

    This fixes either Temporary Directory Hijacking, or Temporary Directory Local Information Disclosure.
    
    Weakness: CWE-379: Creation of Temporary File in Directory with Insecure Permissions
    Severity: High
    CVSSS: 7.3
    Detection: CodeQL & OpenRewrite (https://public.moderne.io/recipes/org.openrewrite.java.security.UseFilesCreateTempDirectory)
    
    Reported-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
    Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
    
    Bug-tracker: JLLeitschuh/security-research#10
    
    Co-authored-by: Moderne <team@moderne.io>
    JLLeitschuh and TeamModerne committed Jul 27, 2022
    Copy the full SHA
    7c6be3e View commit details
    Browse the repository at this point in the history

Commits on Jul 28, 2022

  1. Copy the full SHA
    48ad6dd View commit details
    Browse the repository at this point in the history
  2. Update copyright end year

    violetagg committed Jul 28, 2022
    Copy the full SHA
    7647752 View commit details
    Browse the repository at this point in the history