Security Advisory
CVE-2022-24913
5.5
MEDIUM
Vulnerability Description
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
Published Date
January 12, 2023
Official Source
NIST NVD Advisory