VDB
Sign up
LOW3.3

GHSA-5mg8-w23w-74h3

Information Disclosure in Guava

Quick fix

GHSA-5mg8-w23w-74h3 — com.google.guava:guava: upgrade to the fixed version with the command below.

# pom.xml: bump <version>32.0.0-android</version> for com.google.guava:guava

Details

A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava `com.google.common.io.Files.createTempDir()`. The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.google.guava:guava
Introduced in: 0Fixed in: 32.0.0-android
Fix# pom.xml: bump <version>32.0.0-android</version> for com.google.guava:guava

References