CVE-2022-24913

CVSS V2 None CVSS V3 None
Description
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
Overview
  • CVE ID
  • CVE-2022-24913
  • Assigner
  • report@snyk.io
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-12T05:15:11
  • Last Modified Date
  • 2023-01-20T19:46:40
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:java-merge-sort_project:java-merge-sort:*:*:*:*:*:*:*:* 1 OR 1.1.0
History
Created Old Value New Value Data Type Notes
2023-01-12 05:19:21 Added to TrackCVE
2023-01-12 14:15:41 2023-01-12T13:55:56 CVE Modified Date updated
2023-01-12 14:15:41 Received Awaiting Analysis Vulnerability Status updated
2023-01-18 16:16:14 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-20 21:13:55 2023-01-20T19:46:40 CVE Modified Date updated
2023-01-20 21:13:55 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-20 21:13:56 Weakness Enumeration new
2023-01-20 21:13:57 CPE Information updated