DirectorySecurity Advisories
Sign In
Security Advisories

CGA-crm9-p3mr-qc4q

Published

Last updated

https://images.chainguard.dev/security/CGA-crm9-p3mr-qc4q
Package

thingsboard

Latest Update
Fixed
Fixed Version

3.7-r1

Aliases
  • CVE-2020-29582
  • GHSA-cqj8-47ch-rvvq

Severity

5.3

Medium

CVSS V3

Summary

Incorrect Default Permissions in JetBrains Kotlin

Description

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images