​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-v8xq-jj26-jf85

Published

Last updated

https://images.chainguard.dev/security/CGA-v8xq-jj26-jf85
Package

keycloak

Latest Update
Not affected
Aliases
  • CVE-2020-8908
  • GHSA-5mg8-w23w-74h3

Severity

3.3

Low

CVSS V3

Summary

Information Disclosure in Guava

Description

A temp directory creation vulnerability exists in Guava prior to version 32.0.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open. Maintainers recommend explicitly changing the permissions after the creation of the directory, or removing uses of the vulnerable method.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images