cowtowncoder/java-merge-sort

cowtowncoder/java-merge-sort

Releases18
Frequency7 months 4 weeks
Last Release
Stars89
Basic stand-alone disk-based N-way merge sort component for Java

CVE History

CVEPublishedCVSS v3CVSS v2
5.5 MEDIUM

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.