• CVE-2023-2976

发布时间: 2023年7月8日

修改时间: 2024年3月27日

概要

Use of Java s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.

CVSS v3 指标

NVD openEuler
CVSS评分 7.1 7.1
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality High High
Integrity High High
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1517 guava security update 2023年7月8日

影响产品

产品 状态
KY3.4-4A guava Fixed
KY3.4-5A guava Fixed
KY3.5.1 guava Fixed
KY3.5.2 guava Fixed