QID 980276
QID 980276: Java (maven) Security Update for com.google.guava:guava (GHSA-5mg8-w23w-74h3)
A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. We recommend updating Guava to version 30.0 or later, or update to Java 7 or later, or to explicitly change the permissions after the creation of the directory if neither are possible.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5mg8-w23w-74h3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-5mg8-w23w-74h3 -
github.com/advisories/GHSA-5mg8-w23w-74h3
CVEs related to QID 980276
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5mg8-w23w-74h3 | com.google.guava:guava |
|