CVE-2022-24913: Java Merge-sort Insecure Temporary File vulnerability
(updated )
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 is vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
References
Detect and mitigate CVE-2022-24913 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →