Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
[
{
"signature_version": "v1",
"id": "CVE-2022-24913-1a053058",
"source": "https://github.com/cowtowncoder/java-merge-sort/commit/450fdee70b5f181c2afc5d817f293efa1a543902",
"target": {
"file": "src/main/java/com/fasterxml/sort/std/StdTempFileProvider.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"14677320851492384218221259449265214697",
"136242639063738787493988346133491562375",
"134291028032378787931777221754141333869",
"329401078967520709774943948019203546797",
"80487557871319226811111347270159715406",
"155676590831888048165009876602608533292"
]
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"id": "CVE-2022-24913-c7157514",
"source": "https://github.com/cowtowncoder/java-merge-sort/commit/450fdee70b5f181c2afc5d817f293efa1a543902",
"target": {
"function": "provide",
"file": "src/main/java/com/fasterxml/sort/std/StdTempFileProvider.java"
},
"deprecated": false,
"digest": {
"length": 128.0,
"function_hash": "99739631472293076589966071746306765604"
},
"signature_type": "Function"
}
]