GHSA-q4hm-fwc9-hmv6

    Dashboard / Vulnerabilities / GHSA-q4hm-fwc9-hmv6

    GHSA-q4hm-fwc9-hmv6

    Published: 16 Jun 2021Last Modified: 13 Mar 2026

    Summary: Insecure temporary file used in com.squareup:connect

    Details: This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary file with the permissions bits of -rw-r--r-- on unix-like systems. On unix-like systems, the system temporary directory is shared between users. As such, the contents of the file downloaded by downloadFileFromResponse will be visible to all other users on the local system. A workaround fix for this issue is to set the system property java.io.tmpdir to a safe directory as remediation. Note: This version of the SDK is end of life and no longer maintained, please upgrade to the latest version.

    Affected packages

    Package

    Name: com.squareup:connect

    Purl: pkg:maven/com.squareup/connect

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    2.0.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q4hm-fwc9-hmv6 | CVE-DB