scala: Privilege escalation in Scala compilation daemon
Published Nov 15, 2017
7.8
HIGHCVSS 3.1
EPSS 0.35%
Description
The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.
Affected products
No data.
- < 2.10.7
- ≥ 2.11.0 · < 2.11.12
- ≥ 2.12.0 · < 2.12.4
No data.
JBoss Developer Studio 10
scala-compiler
Not affected
JBoss Developer Studio 10
scala-library
Not affected
JBoss Developer Studio 8
scala-library
Not affected
Red Hat JBoss A-MQ 6
scala-library
Not affected
Red Hat JBoss Data Grid 6
scala-library
Will not fix
Red Hat JBoss Data Grid 7
scala-library
Not affected
Red Hat JBoss Data Virtualization 6
scala-library
Not affected
Red Hat JBoss Fuse 6
camel
Not affected
Red Hat JBoss Fuse Service Works 6
camel-scala
Will not fix
Red Hat JBoss Fuse Service Works 6
scala-compiler
Will not fix
Red Hat JBoss Fuse Service Works 6
scala-library
Will not fix
Red Hat Software Collections
rh-scala210-scala
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Developer Studio 10 | scala-compiler | Not affected | n/a |
| JBoss Developer Studio 10 | scala-library | Not affected | n/a |
| JBoss Developer Studio 8 | scala-library | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | scala-library | Not affected | n/a |
| Red Hat JBoss Data Grid 6 | scala-library | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | scala-library | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | scala-library | Not affected | n/a |
| Red Hat JBoss Fuse 6 | camel | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | camel-scala | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | scala-compiler | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | scala-library | Will not fix | n/a |
| Red Hat Software Collections | rh-scala210-scala | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
1. Use "scala -nocompdaemon MyScript.scala" rather than "scala MyScript.scala" to disable the implicit startup and use of the daemon. 2. Avoid explicitly starting fsc. This text is borrowed from the upstream security advisory.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.35% (0.00346) | 25.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.38% (0.00375) | 29.04th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.12% (0.00116) | 27.88th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 11.89th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 8.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.21% (0.02205) | 50.62th | v1 |
| Jan 6, 2022 | 2.21% (0.02205) | 50.12th | v1 |
| Sep 1, 2021 | 2.21% (0.02205) | 77.51th | v1 |
| Apr 14, 2021 | 2.21% (0.02205) | 0.00th | v1 |
References (38)
- http://scala-lang.org/news/security-update-nov17.html x_refsource_CONFIRMIssue TrackingMitigationVendor Advisory
- https://access.redhat.com/security/cve/CVE-2017-15288 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1516915 Issue Tracking
- https://github.com/advisories/GHSA-qvxv-pmq9-4q7g Advisory
- https://github.com/scala/scala/pull/6108 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/scala/scala/pull/6120 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/scala/scala/pull/6128 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://lists.apache.org/thread.html/r10dd8e5b3bbe3bb531aa4a65472ce56f91efbb77ea9fe04bb8272e2c%40%3Cjira.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r10dd8e5b3bbe3bb531aa4a65472ce56f91efbb77ea9fe04bb8272e2c@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r18a05115cfa078c0f4e5c1ea2e8d64804f63e0095aa2174a3afecc0f%40%3Cjira.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r18a05115cfa078c0f4e5c1ea2e8d64804f63e0095aa2174a3afecc0f@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r1d51eae81ceb7bfd1780936a48b460ab31d53ff2ed526a88a7f60fe4%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1d51eae81ceb7bfd1780936a48b460ab31d53ff2ed526a88a7f60fe4@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r32e0b1d5ff43ac3ed4b179a4e663022d1c5ccac77884a99ea149e633%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r32e0b1d5ff43ac3ed4b179a4e663022d1c5ccac77884a99ea149e633@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r33665e9213cc6df1e48c3d99d1b0c7a3203e9bd0ef4fc4ba838bcb04%40%3Cjira.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r33665e9213cc6df1e48c3d99d1b0c7a3203e9bd0ef4fc4ba838bcb04@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r3f10022ec972c8df29a950d1a591c16562eeddd9194d3010e46b9b76%40%3Cjira.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3f10022ec972c8df29a950d1a591c16562eeddd9194d3010e46b9b76@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r5a1418a4f5101f5af3fc14bf358c54f2c7200e6a3701de2e2f581e1b%40%3Cdev.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5a1418a4f5101f5af3fc14bf358c54f2c7200e6a3701de2e2f581e1b@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r628ea3ea2fed4d9c1c5232a0b1ed108a15abc9fd2f0aaca1e8cc9164%40%3Cdev.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r628ea3ea2fed4d9c1c5232a0b1ed108a15abc9fd2f0aaca1e8cc9164@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/re72f4d04dfc398aae0e38dbfeccf44780df2782623a610cbfcec6f3a%40%3Cjira.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re72f4d04dfc398aae0e38dbfeccf44780df2782623a610cbfcec6f3a@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rf57e4d7211b30e51803911304f3b7b54393f7a4bd60bb0784c31eec1%40%3Cjira.kafka.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf57e4d7211b30e51803911304f3b7b54393f7a4bd60bb0784c31eec1@%3Cjira.kafka.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2017-15288
- https://security.gentoo.org/glsa/201812-08 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-15288
Change history (0)
No recorded changes yet.