Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
{
"cwe_ids": [
"CWE-377",
"CWE-668"
],
"github_reviewed_at": "2023-01-12T20:55:23Z",
"nvd_published_at": "2023-01-12T05:15:00Z",
"github_reviewed": true,
"severity": "MODERATE"
}