CWE Database
/

CWE-377

Back to CWE list

CWE-377

Insecure Temporary File

Class
Incomplete

Description

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Common Consequences

Scope

Confidentiality
Integrity

Impact

Read Files or Directories, Modify Files or Directories

CVE-2022-41954

A library uses the Java File.createTempFile() method which creates a file with "-rw-r--r--" default permissions on Unix-like operating systems

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now