icon

We found results for “

CVE-2021-21429

Good to know:

icon
icon

Date: April 27, 2021

OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically given an OpenAPI Spec. Using "File.createTempFile" in JDK will result in creating and using insecure temporary files that can leave application and system data vulnerable to attacks. OpenAPI Generator maven plug-in creates insecure temporary files during the process. The issue has been patched with "Files.createTempFile" and released in the v5.1.0 stable version.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Files or Directories Accessible to External Parties

CWE-552

Creation of Temporary File With Insecure Permissions

CWE-378

Creation of Temporary File in Directory with Insecure Permissions

CWE-379

Insecure Temporary File

CWE-377

Top Fix

icon

Upgrade Version

Upgrade to version org.openapitools:openapi-generator-maven-plugin:5.1.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): LOCAL
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): NONE
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us