Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqj8-47ch-rvvq

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Incorrect Default Permissions in JetBrains Kotlin

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

Пакеты

Наименование

org.jetbrains.kotlin:kotlin-stdlib

maven
Затронутые версииВерсия исправления

<= 1.4.20

1.4.21

EPSS

Процентиль: 0%
0.00004
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVSS3: 5.3
redhat
около 5 лет назад

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVSS3: 5.3
nvd
около 5 лет назад

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVSS3: 5.3
debian
около 5 лет назад

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for ...

CVSS3: 5.3
fstec
около 5 лет назад

Уязвимость интерпретатора языка программирования JetBrains Kotlin, связанная с неправильными настройками прав доступа по умолчанию, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 0%
0.00004
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-276