spring-boot is vulnerable to Insecure Temporary File
60
Medium Risk
Affected versions of this package are vulnerable to improper link resolution when writing PID files because ApplicationPidFileWriter may follow symlinks at a predictable file path. A local attacker with write access to the PID file location may cause arbitrary file corruption each time the application starts.
You are affected if using a vulnerable version.
spring-boot is vulnerable to Insecure Temporary File in versions 2.7.0 - 2.7.32, 3.3.0 - 3.3.18, 3.4.0 - 3.4.15, 3.5.0 - 3.5.13 and 4.0.0 - 4.0.5.
Upgrade the org.springframework.boot:spring-boot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant