OESA-2021-1049
Dashboard / Vulnerabilities / OESA-2021-1049
Summary: guava security update
Details: Guava is a set of core Java libraries from Google that includes new collection types (such as multimap and multiset), immutable collections, a graph library, and utilities for concurrency, I/O, hashing, caching, primitives, strings, and more! It is widely used on most Java projects within Google, and widely used by many other companies as well. Security Fix(es): A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. We recommend updating Guava to version 30.0 or later, or update to Java 7 or later, or to explicitly change the permissions after the creation of the directory if neither are possible.(CVE-2020-8908)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1049, https://nvd.nist.gov/vuln/detail/CVE-2020-8908
Affected packages
Package
Name: guava
Purl: pkg:rpm/openEuler/guava&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
