QID 980901
QID 980901: Java (maven) Security Update for org.scala-lang:scala-compiler (GHSA-qvxv-pmq9-4q7g)
The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qvxv-pmq9-4q7g for updates pertaining to this vulnerability.
Vendor References
- GHSA-qvxv-pmq9-4q7g -
github.com/advisories/GHSA-qvxv-pmq9-4q7g
CVEs related to QID 980901
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qvxv-pmq9-4q7g | org.scala-lang:scala-compiler |
|