CWE · MITRE source
CWE-379Creation of Temporary File in Directory with Insecure Permissions
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.
On some operating systems, the fact that the temporary file exists may be apparent to any user with sufficient privileges to access that directory. Since the file is visible, the application that is using the temporary file could be known. If one has access to list the processes on the system, the attacker has gained information about what the user is doing at that time. By correlating this with the applications the user is running, an attacker could potentially discover what a user's actions are. From this, higher levels of security could be breached.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): STIG oracle linux 8 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A01:2025 Broken Access Control.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2020-11979 UPD | 6.7 | 7.5 | 0.0824 | 2020-10-01 |
CVE-2023-26396 UPD | 6.4 | 7.8 | 0.0403 | 2023-04-12 |
CVE-2021-29428 UPD | 6.2 | 8.8 | 0.0053 | 2021-04-13 |
CVE-2021-21100 UPD | 6.2 | 7.8 | 0.0172 | 2021-04-15 |
CVE-2016-9486 UPD | 6.1 | 7.8 | 0.0123 | 2018-07-13 |
CVE-2022-23950 UPD | 6.1 | 7.5 | 0.0133 | 2022-09-21 |
CVE-2023-49797 UPD | 6.1 | 8.8 | 0.0032 | 2023-12-09 |
CVE-2025-27148 UPD | 6.0 | 8.8 | 0.0024 | 2025-02-25 |
CVE-2025-32438 UPD | 6.0 | 8.8 | 0.0018 | 2025-04-15 |
CVE-2020-27216 UPD | 5.9 | 7.0 | 0.0435 | 2020-10-23 |
CVE-2026-14551 | 5.9 | 8.8 | 0.0013 | 2026-07-22 |
CVE-2021-40708 UPD | 5.8 | 7.3 | 0.0169 | 2021-09-29 |
CVE-2023-21611 UPD | 5.8 | 7.8 | 0.0040 | 2023-01-18 |
CVE-2023-21612 UPD | 5.8 | 7.8 | 0.0040 | 2023-01-18 |
CVE-2024-9950 UPD | 5.8 | 7.8 | 0.0031 | 2025-01-02 |
CVE-2025-21173 UPD | 5.8 | 7.3 | 0.0124 | 2025-01-14 |
CVE-2023-3972 UPD | 5.7 | 7.8 | 0.0027 | 2023-11-01 |
CVE-2024-36821 UPD | 5.7 | 6.8 | 0.0290 | 2024-06-11 |
CVE-2023-6080 UPD | 5.7 | 7.8 | 0.0022 | 2024-10-18 |
CVE-2024-9500 UPD | 5.7 | 7.8 | 0.0019 | 2024-11-15 |
CVE-2023-37243 UPD | 5.6 | 7.8 | 0.0018 | 2023-10-31 |
CVE-2023-3181 UPD | 5.6 | 7.8 | 0.0018 | 2024-01-25 |
CVE-2021-28613 UPD | 5.4 | 7.4 | 0.0049 | 2021-09-27 |
CVE-2021-39827 UPD | 5.3 | 6.5 | 0.0150 | 2021-09-27 |
CVE-2021-21290 UPD | 5.2 | 6.2 | 0.0178 | 2021-02-08 |