Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25438
HistoryMay 15, 2020 - 5:16 a.m.

Insecure Temporary Directory

2020-05-1505:16:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.001 Low

EPSS

Percentile

33.0%

ant uses an insecure temporary directory. The system property java.io.tempdir causes insecure permissions to be set on a directory, allowing local users to access the temporary directory or write arbitrary files into it. This could also lead to an attacker injecting modified source files into the build process.

References