GHSA-c43q-5hpj-4crv
MODERATECVE-2021-28168Eclipse Jersey 2.28 - 2.33 and Eclipse Jersey 3.0.0 - 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitiv
- Affected
- >= 3.0.0, <= 3.0.1, >= 2.28, <= 2.33
- Fixed in
- 3.0.2
- Weakness
- CWE-378
- Published
- 2021-04-23
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference