mpxj is vulnerable to Insecure Temporary File
33
Low Risk
MPXJ extracts the contents of P3 PRX files, SureTrak STX files, and other zip-compressed schedule files into a temporary directory that is created with default world-readable permissions. While a schedule is being read, and before the temporary directory is deleted, another local user on the same host can read the extracted schedule contents. This briefly exposes potentially sensitive project data to unauthorized local users. The fix creates the temporary extraction directory with restricted permissions so its contents are no longer world-readable.
You are affected if you are using a version that falls within the vulnerable range and you read P3 PRX files, SureTrak STX files, or zip-compressed schedule files on a host where other local users can access the shared temporary directory.
mpxj is vulnerable to Insecure Temporary File in versions 7.3.0 - 16.5.0.
Upgrade the net.sf.mpxj:mpxj library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant