QID 982893
QID 982893: Java (maven) Security Update for io.swagger:swagger-codegen (GHSA-pc22-3g76-gm6j)
Security update has been released for io.swagger:swagger-codegen to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory.
This vulnerability is local privilege escalation because the contents of the `outputFolder` can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled.
* https://github.com/swagger-api/swagger-codegen/commit/987ea7a30b463cc239580d6ad166c707ae942a89
included in release: 2.4.19
- GHSA-pc22-3g76-gm6j -
github.com/advisories/GHSA-pc22-3g76-gm6j
CVEs related to QID 982893
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pc22-3g76-gm6j | io.swagger:swagger-codegen |
|