CVE-2020-8908
ADVISORY - githubSummary
A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.
Common Weakness Enumeration (CWE)
NIST
CVSS SCORE
3.3lowGitHub
CVSS SCORE
3.3lowDebian
-
Ubuntu
1.8
CVSS SCORE
3.3mediumRed Hat
CVSS SCORE
3.3lowChainguard
CGA-3f7x-7jf4-vmjh
-
Chainguard
CGA-4jpf-w26h-cg9j
-
Chainguard
CGA-7rjh-334q-pq8g
-
Chainguard
CGA-9wv6-wh8w-g624
-
Chainguard
CGA-c59f-3389-82hg
-
Chainguard
CGA-c5f6-f2ff-f6g9
-
Chainguard
CGA-cffm-4mv2-8x2h
-
Chainguard
CGA-f85c-8jfc-2g85
-
Chainguard
CGA-gpmg-5xqr-j8wx
-
Chainguard
CGA-m9rw-cj52-34gw
-
Chainguard
CGA-mh7m-jqq7-vcwx
-
Chainguard
CGA-v32h-rq8v-hch4
-
Chainguard
CGA-v8xq-jj26-jf85
-
Chainguard
CGA-vm4c-5phc-7w2r
-
Chainguard
CGA-w93v-xw63-rv54
-
intheWild
-
-
minimos
MINI-6v82-xxhc-833r
-
minimos
MINI-cj6f-jcp2-h8wf
-
minimos
MINI-hg4x-q55j-j34g
-
minimos
MINI-hq3q-c9h7-v8g9
-
minimos
MINI-m6x8-rq5f-j7jr
-
minimos
MINI-pqhr-wqwq-3x94
-