- 19 11月, 2022 1 次提交
-
-
由 Jonathan Leitschuh 提交于
This fixes temporary file information disclosure vulnerability due to the use of the vulnerable `File.createTempFile()` method. The vulnerability is fixed by using the `Files.createTempFile()` method which sets the correct posix permissions. Weakness: CWE-377: Insecure Temporary File Severity: Medium CVSSS: 5.5 Detection: CodeQL & OpenRewrite (https://public.moderne.io/recipes/org.openrewrite.java.security.SecureTempFileCreation) Reported-by: NJonathan Leitschuh <Jonathan.Leitschuh@gmail.com> Signed-off-by: NJonathan Leitschuh <Jonathan.Leitschuh@gmail.com> Bug-tracker: https://github.com/JLLeitschuh/security-research/issues/18Co-authored-by: NModerne <team@moderne.io>
-
- 09 11月, 2021 1 次提交
-
-
由 MaxKey 提交于
-
- 15 2月, 2021 1 次提交
-
-
由 MaxKey 提交于
-
- 05 7月, 2020 1 次提交
-
-
由 MaxKey单点登录官方 提交于
licenses
-
- 29 4月, 2019 1 次提交
-
-
由 MaxKey单点登录官方 提交于
-