Skip to content

HTSJDK is vulnerable to exposure of resource(s) to the wrong sphere

High severity GitHub Reviewed Published Nov 29, 2022 to the GitHub Advisory Database • Updated Jan 28, 2023

Package

maven com.github.samtools:htsjdk (Maven)

Affected versions

< 3.0.1

Patched versions

3.0.1

Description

The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary directory before attempting to create it.

References

Published by the National Vulnerability Database Nov 29, 2022
Published to the GitHub Advisory Database Nov 29, 2022
Reviewed Dec 2, 2022
Last updated Jan 28, 2023

Severity

High
7.8
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

CVE-2022-21126

GHSA ID

GHSA-96vh-4rfp-c42c

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.