CVE-2021-21429

Files or Directories Accessible to External Parties in maven/org.openapitools/openapi-generator

Identifiers

CVE-2021-21429, GHSA-867q-77cc-98mv

Package Slug

maven/org.openapitools/openapi-generator

Vulnerability

Files or Directories Accessible to External Parties

Description

OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using File.createTempFile in JDK will result in creating and using insecure temporary files that can leave application and system data vulnerable to attacks. OpenAPI Generator maven plug-in creates insecure temporary files during the process.

Affected Versions

All versions before 5.1.0

Solution

Upgrade to version 5.1.0 or above.

Last Modified

2021-05-10

source