VDB
BDU%3A2021-02413
BDU%3A2021-02413
PUBLISHED
CVSS 1.7000000476837158 LOW
Уязвимость реализации функции Files.createTempDir() набора Java-библиотек Google Guava, позволяюшая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
1.7000000476837158
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Oracle Corp., Google Inc, Apache Software Foundation, Elastic NV | OpenShift Container Platform, Red Hat Satellite, Jboss Fuse, OpenShift Application Runtimes, Red Hat Single Sign-On, Red Hat Descision Manager, JBoss Enterprise Application Platform, Red Hat AMQ Broker, JBoss A-MQ, CodeReady Studio, NoSQL Database, Guava, Red Hat build of Quarkus, Red Hat Integration Camel K, Red Hat Integration Service Registry, Cassandra, Maven, Logstash, Android Studio |
Timeline
- May 12, 2021 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40 url
- https://github.com/google/guava/issues/4011 url
- https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e@%3Ccommits.ws.apache.org%3E url
- https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748@%3Ccommits.pulsar.apache.org%3E url
- https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6@%3Ccommits.cxf.apache.org%3E url
- https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222@%3Ccommits.ws.apache.org%3E url
- https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba@%3Cissues.maven.apache.org%3E url
- https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf@%3Ccommits.cxf.apache.org%3E url
- https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3@%3Ctorque-dev.db.apache.org%3E url
- https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a@%3Ctorque-dev.db.apache.org%3E url
- https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604@%3Ctorque-dev.db.apache.org%3E url
- https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415 url
- https://www.oracle.com/security-alerts/cpuapr2021.html url
- https://access.redhat.com/security/cve/cve-2020-8908 url