GHSA-7g45-4rm6-3mm3

    Dashboard / Vulnerabilities / GHSA-7g45-4rm6-3mm3

    GHSA-7g45-4rm6-3mm3

    Published: 14 Jun 2023Last Modified: 10 Sept 2026
    Aliases:

    Summary: Guava vulnerable to insecure use of temporary directory

    Details: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.

    Affected packages

    Package

    Name: com.google.guava:guava

    Purl: pkg:maven/com.google.guava/guava

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.0
    Fixed -32.0.0-android

    Affected versions

    10.0
    10.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7g45-4rm6-3mm3 | CVE-DB