FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Fix: Vulnerability for guava by Krish-cloudsufi · Pull Request #614 · data-integrations/database-plugins · GitHub

Fix: Vulnerability for guava - #614

Open
Krish-cloudsufi wants to merge 1 commit into
data-integrations:developfrom
cloudsufi:guava
Open

Fix: Vulnerability for guava#614
Krish-cloudsufi wants to merge 1 commit into
data-integrations:developfrom
cloudsufi:guava

Conversation

Copy link
Copy Markdown

Issue:
Resolved a high-severity information disclosure vulnerability (GHSA-7g45-4rm6-3mm3) related to insecure temporary file handling in the FileBackedOutputStream class of the Guava library (com.google.guava:guava). This vulnerability affects versions 1.0 through 31.1 on Unix-based systems and Android Ice Cream Sandwich. In vulnerable versions, temporary files were created in the system's default temporary directory (/tmp), allowing local users or applications with access to the directory to potentially read or tamper with those files.

Root Cause:
Guava used Java's default temporary directory for storing files without proper isolation, which could expose sensitive data in shared environments.

Fix:
Upgraded guava version from 13.0.1 to 32.1.3-jre

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL