QID 982832

QID 982832: Java (maven) Security Update for com.netflix.priam:priam (GHSA-f4jh-ww96-9h9j)

Security update has been released for com.netflix.priam:priam to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

When `File.createTempFile` creates a file, the permissions on that file are -rw-r--r--. This means that other users can read the contents of these files after they are written, although they can not modify the contents. This allows for local information disclosure if these files contain sensitive information.

Vulnerable locations:
- https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/backup/MetaData.java#L106-L111
- https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/identity/DoubleRing.java#L109-L118
- https://github.com/Netflix/Priam/blob/362660bb7ebddb0cfa756a282d94678f65af9f06/priam/src/main/java/com/netflix/priam/restore/PostRestoreHook.java#L80-L86

---

The custom CodeQL queries leveraged to find these this as well as their results can be found here:

https://lgtm.com/query/1543383251073929777/
https://lgtm.com/query/3142895023158674709/

## Official Disclosure

https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2021-002.md

## Fix

There are no fixed versions.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to refer to GHSA-f4jh-ww96-9h9j for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982832

    Software Advisories
    Advisory ID Software Component Link
    GHSA-f4jh-ww96-9h9j com.netflix.priam:priam URL Logo github.com/advisories/GHSA-f4jh-ww96-9h9j