Launch Week Day 1: Announcing Security Design Review
LOW 3.3 Maven

Information Disclosure in Guava

GHSA-5mg8-w23w-74h3 · CVE-2020-8908

Published · Modified

Description

A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes