Описание
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
Отчет
Red Hat CodeReady Studio 12 is not affected by this vulnerability because It ships kotlin-stdlib. The vulnerable component is not in kotlin-stdlib.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat CodeReady Studio 12 | kotlin-stdlib | Not affected | ||
| Red Hat Integration Service Registry | kotlin-scripting-jvm | Not affected | ||
| Red Hat Fuse 7.11 | kotlin-scripting-jvm | Fixed | RHSA-2022:5532 | 07.07.2022 |
| Red Hat Integration | kotlin-scripting-jvm | Fixed | RHSA-2021:3205 | 18.08.2021 |
| Red Hat Integration Camel Quarkus 2 | kotlin-scripting-jvm | Fixed | RHSA-2021:3207 | 18.08.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for ...
Incorrect Default Permissions in JetBrains Kotlin
Уязвимость интерпретатора языка программирования JetBrains Kotlin, связанная с неправильными настройками прав доступа по умолчанию, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.3 Medium
CVSS3