MEDIUM5.3
GHSA-cqj8-47ch-rvvq
Incorrect Default Permissions in JetBrains Kotlin
Quick fix
GHSA-cqj8-47ch-rvvq — org.jetbrains.kotlin:kotlin-stdlib: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.4.21</version> for org.jetbrains.kotlin:kotlin-stdlibDetails
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.jetbrains.kotlin:kotlin-stdlib
Introduced in:
0Fixed in: 1.4.21Fix
# pom.xml: bump <version>1.4.21</version> for org.jetbrains.kotlin:kotlin-stdlibReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-29582[ADVISORY]
- https://blog.jetbrains.com[WEB]
- https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020[WEB]
- https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E[WEB]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuapr2022.html[WEB]
- https://www.oracle.com/security-alerts/cpujan2022.html[WEB]