CVE-2022-21126 – com.github.samtools:htsjdk
Package
Manager: maven
Name: com.github.samtools:htsjdk
Vulnerable Version: >=0 <3.0.1
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00055 pctl0.17189
Details
HTSJDK is vulnerable to exposure of resource(s) to the wrong sphere The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary directory before attempting to create it.
Metadata
Created: 2022-11-29T18:30:18Z
Modified: 2022-12-02T22:21:13Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-96vh-4rfp-c42c/GHSA-96vh-4rfp-c42c.json
CWE IDs: ["CWE-668"]
Alternative ID: GHSA-96vh-4rfp-c42c
Finding: F017
Auto approve: 1