LOW 3.3 Maven

Information Disclosure in Guava

GHSA-5mg8-w23w-74h3 · CVE-2020-8908 · SNYK-JAVA-COMGOOGLEGUAVA-1015415

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes