• CVE-2023-2976

发布时间: 2023年7月8日

修改时间: 2024年10月31日

概要

Use of Java s default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.

CVSS v3 指标

NVD openEuler
Confidentiality High High
Attack Vector Local Local
CVSS评分 7.1 7.1
Attack Complexity Low Low
Privileges Required Low Low
Scope Unchanged Unchanged
Integrity High High
User Interaction None None
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1517 guava security update 2023年7月8日
KylinSec-SA-2023-1518 guava20 security update 2023年7月8日

影响产品

产品 状态
KY3.4-4A guava20 Fixed
KY3.4-5A guava20 Fixed
KY3.5.1 guava20 Fixed
KY3.5.2 guava20 Fixed