Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit e4c017e

Browse files
JLLeitschuhaibaars
andcommitted
Apply suggestions from code review
Co-authored-by: Arthur Baars <[email protected]>
1 parent 13fed0e commit e4c017e

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

java/ql/src/Security/CWE/CWE-200/TempDirLocalInformationDisclosure.qhelp

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,9 @@ can occur.</p>
2121
<ul>
2222
<li><a href="https://docs.oracle.com/javase/8/docs/api/java/nio/file/Files.html#createTempDirectory">java.nio.file.Files#createTempDirectory</a></li>
2323
<li><a href="https://docs.oracle.com/javase/8/docs/api/java/nio/file/Files.html#createTempFile">java.nio.file.Files#createTempFile</a></li>
24-
<ul>
25-
Otherwise, create the file/directory by manually specificfying the expected posix file permissions.
26-
Eg. <code>PosixFilePermissions.asFileAttribute(EnumSet.of(PosixFilePermission.OWNER_READ, PosixFilePermission.OWNER_WRITE))</code>
24+
</ul>
25+
<p>Otherwise, create the file/directory by manually specificfying the expected posix file permissions.
26+
Eg. <code>PosixFilePermissions.asFileAttribute(EnumSet.of(PosixFilePermission.OWNER_READ, PosixFilePermission.OWNER_WRITE))</code></p>
2727
<ul>
2828
<li><a href="https://docs.oracle.com/javase/8/docs/api/java/nio/file/Files.html#createFile-java.nio.file.Path-java.nio.file.attribute.FileAttribute...-">java.nio.file.Files#createFile</a></li>
2929
<li><a href="https://docs.oracle.com/javase/8/docs/api/java/nio/file/Files.html#createDirectory-java.nio.file.Path-java.nio.file.attribute.FileAttribute...-">java.nio.file.Files#createDirectory</a></li>
@@ -39,9 +39,10 @@ Eg. <code>PosixFilePermissions.asFileAttribute(EnumSet.of(PosixFilePermission.OW
3939
<p>In the following example, files and directories are created with file permissions protecting their contents.</p>
4040

4141
<sample src="TempDirUsageSafe.java"/>
42+
</example>
4243

4344
<references>
4445
<li>OSWAP: <a href="https://owasp.org/www-community/vulnerabilities/Insecure_Temporary_File">Insecure Temporary File</a>.</li>
45-
<li>CERT: <a href="https://wiki.sei.cmu.edu/confluence/display/java/FIO00-J.+Do+not+operate+on+files+in+shared+directories">FIO00-J. Do not operate on files in shared directories</a>
46+
<li>CERT: <a href="https://wiki.sei.cmu.edu/confluence/display/java/FIO00-J.+Do+not+operate+on+files+in+shared+directories">FIO00-J. Do not operate on files in shared directories</a></li>
4647
</references>
4748
</qhelp>

0 commit comments

Comments
 (0)