imageio-icns is vulnerable to Insecure Temporary File
27
Low Risk
SipsJP2Reader.dumpToFile in the imageio-icns plugin also uses File.createTempFile to write a temporary PNG when decoding an ICNS image containing a JPEG2000 payload via the macOS sips tool, creating that file with default umask-based (typically world-readable) permissions. Any other local user on a shared host can read the dumped image data while the reader runs. The fix switches to Files.createTempFile, which restricts the file to owner-only permissions.
You are affected if you are using a version that falls within the vulnerable range and you decode ICNS images containing JPEG2000 data on macOS, where the reader shells out to sips, on a shared or multi-user host.
imageio-icns is vulnerable to Insecure Temporary File in versions 3.0 - 3.14.0.
Upgrade the com.twelvemonkeys.imageio:imageio-icns library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.