Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://huntr.dev/bounties/7e50397b-dd63-4bb5-b56d-704094a7da45 | issue tracking third party advisory patch |
https://github.com/horovod/horovod/commit/b96ecae4dc69fc0a83c7c2d3f1dde600c20a1b41 | third party advisory patch |