common-io is vulnerable to Insecure Temporary File
27
Low Risk
FileCacheSeekableStream.createTempFile in common-io creates its on-disk image cache files with File.createTempFile, which honors the process umask and is typically world-readable. Any other local user on a shared or multi-user host can read cached image data while TwelveMonkeys caches a stream to disk. ImageIO readers that enable disk-based stream caching go through this path. The fix switches to Files.createTempFile, which creates the file with owner-only permissions.
You are affected if you are using a version that falls within the vulnerable range and image reading uses on-disk stream caching on a shared or multi-user host.
common-io is vulnerable to Insecure Temporary File in versions 3.0 - 3.14.0.
Upgrade the common-io library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.