First published: Mon May 10 2021(Updated: )
Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system. The issue has been patched with `Files.createTempFile` and released in the v5.1.0 stable version.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21428 has been classified as a moderate severity vulnerability due to the potential for information leakage.
To fix CVE-2021-21428, update your OpenAPI Generator to version 5.1.0 or later.
CVE-2021-21428 affects all versions of OpenAPI Generator prior to 5.1.0.
The impact of CVE-2021-21428 includes the creation of insecure temporary folders that can expose sensitive data.
CVE-2021-21428 can potentially be exploited locally if an attacker has access to the environment where the vulnerable software is running.