Use of temporary directory for file creation in `FileBackedOutputStream` in Guava
Published Jun 14, 2023
7.1
HIGHCVSS 3.1
EPSS 0.25%
Description
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
Affected products
-
- Version 1.0StatusaffectedConstraints<32.0.0
- Version
No data.
AMQ Broker 7.11.2
guava
Fixed · RHSA-2023:5491
MTA-6.2-RHEL-8
mta/mta-rhel8-operator:6.2.2-3
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-hub-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-operator-bundle:6.2.2-5
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-pathfinder-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-ui-rhel9:6.2.2-2
Fixed · RHSA-2024:1027
MTA-6.2-RHEL-9
mta/mta-windup-addon-rhel9:6.2.2-3
Fixed · RHSA-2024:1027
OCP-Tools-4.12-RHEL-8
jenkins-0:2.426.3.1706515686-3.el8
Fixed · RHSA-2024:0778
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1706515741-1.el8
Fixed · RHSA-2024:0778
OCP-Tools-4.14-RHEL-8
jenkins-2-plugins-0:4.14.1706516441-1.el8
Fixed · RHSA-2024:0777
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-41
Fixed · RHSA-2024:0801
Red Hat AMQ Streams 2.5.0
n/a
Fixed · RHSA-2023:5165
Red Hat AMQ Streams 2.6.0
guava
Fixed · RHSA-2023:7678
Red Hat AMQ Streams 2.7.0
n/a
Fixed · RHSA-2024:3527
Red Hat JBoss Enterprise Application Platform
com.google.guava/guava:32.1.1.jre-redhat-00001
Fixed · RHSA-2023:7641
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-guava-libraries-0:32.1.1-2.jre_redhat_00001.1.el8eap
Fixed · RHSA-2023:7638
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-guava-libraries-0:32.1.1-2.jre_redhat_00001.1.el9eap
Fixed · RHSA-2023:7639
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-guava-libraries-0:32.1.1-2.jre_redhat_00001.1.el7eap
Fixed · RHSA-2023:7637
Red Hat Single Sign-On 7
guava
Fixed · RHSA-2024:0804
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.12-1.redhat_00001.1.el7sso
Fixed · RHSA-2024:0798
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.12-1.redhat_00001.1.el8sso
Fixed · RHSA-2024:0799
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.12-1.redhat_00001.1.el9sso
Fixed · RHSA-2024:0800
Red Hat build of Apache Camel 4.4.0 for Spring Boot
guava
Fixed · RHSA-2024:2707
Red Hat build of Quarkus 2.13.9.Final
com.google.guava/guava:32.0.1.jre-redhat-00001
Fixed · RHSA-2023:7700
A-MQ Clients 2
guava
Not affected
Cryostat 2
guava
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel8
Not affected
Migration Toolkit for Runtimes
org.jboss.windup-windup-parent
Affected
Red Hat A-MQ Online
guava
Out of support scope
Red Hat Data Grid 8
guava
Not affected
Red Hat Decision Manager 7
guava
Out of support scope
Red Hat Enterprise Linux 7
guava
Out of support scope
Red Hat Enterprise Linux 8
guava
Will not fix
Red Hat Enterprise Linux 9
guava
Will not fix
Red Hat Fuse 7
guava
Will not fix
Red Hat Integration Camel K 1
guava
Will not fix
Red Hat Integration Camel Quarkus 2
guava
Will not fix
Red Hat JBoss Data Grid 7
guava
Out of support scope
Red Hat JBoss Data Virtualization 6
guava
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
guava
Out of support scope
Red Hat JBoss Enterprise Application Platform 8
guava
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
guava
Not affected
Red Hat JBoss Fuse 6
guava
Out of support scope
Red Hat JBoss Fuse Service Works 6
guava
Out of support scope
Red Hat JBoss Web Server 5
guava
Not affected
Red Hat OpenShift Container Platform 4
jenkins
Affected
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Affected
Red Hat OpenStack Platform 13 (Queens)
guava
Out of support scope
Red Hat Process Automation 7
guava
Out of support scope
Red Hat Satellite 6
guava
Not affected
Red Hat build of Apache Camel for Spring Boot 3
guava
Affected
Red Hat build of Apicurio Registry 2
guava
Affected
Red Hat build of Debezium 1
guava
Out of support scope
Red Hat build of Debezium 2
guava
Not affected
Red Hat build of OptaPlanner 8
guava
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| AMQ Broker 7.11.2 | guava | Fixed | RHSA-2023:5491 |
| MTA-6.2-RHEL-8 | mta/mta-rhel8-operator:6.2.2-3 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-hub-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-operator-bundle:6.2.2-5 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-pathfinder-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-ui-rhel9:6.2.2-2 | Fixed | RHSA-2024:1027 |
| MTA-6.2-RHEL-9 | mta/mta-windup-addon-rhel9:6.2.2-3 | Fixed | RHSA-2024:1027 |
| OCP-Tools-4.12-RHEL-8 | jenkins-0:2.426.3.1706515686-3.el8 | Fixed | RHSA-2024:0778 |
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1706515741-1.el8 | Fixed | RHSA-2024:0778 |
| OCP-Tools-4.14-RHEL-8 | jenkins-2-plugins-0:4.14.1706516441-1.el8 | Fixed | RHSA-2024:0777 |
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-41 | Fixed | RHSA-2024:0801 |
| Red Hat AMQ Streams 2.5.0 | n/a | Fixed | RHSA-2023:5165 |
| Red Hat AMQ Streams 2.6.0 | guava | Fixed | RHSA-2023:7678 |
| Red Hat AMQ Streams 2.7.0 | n/a | Fixed | RHSA-2024:3527 |
| Red Hat JBoss Enterprise Application Platform | com.google.guava/guava:32.1.1.jre-redhat-00001 | Fixed | RHSA-2023:7641 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-guava-libraries-0:32.1.1-2.jre_redhat_00001.1.el8eap | Fixed | RHSA-2023:7638 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-guava-libraries-0:32.1.1-2.jre_redhat_00001.1.el9eap | Fixed | RHSA-2023:7639 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-guava-libraries-0:32.1.1-2.jre_redhat_00001.1.el7eap | Fixed | RHSA-2023:7637 |
| Red Hat Single Sign-On 7 | guava | Fixed | RHSA-2024:0804 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.12-1.redhat_00001.1.el7sso | Fixed | RHSA-2024:0798 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.12-1.redhat_00001.1.el8sso | Fixed | RHSA-2024:0799 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.12-1.redhat_00001.1.el9sso | Fixed | RHSA-2024:0800 |
| Red Hat build of Apache Camel 4.4.0 for Spring Boot | guava | Fixed | RHSA-2024:2707 |
| Red Hat build of Quarkus 2.13.9.Final | com.google.guava/guava:32.0.1.jre-redhat-00001 | Fixed | RHSA-2023:7700 |
| A-MQ Clients 2 | guava | Not affected | n/a |
| Cryostat 2 | guava | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel8 | Not affected | n/a |
| Migration Toolkit for Runtimes | org.jboss.windup-windup-parent | Affected | n/a |
| Red Hat A-MQ Online | guava | Out of support scope | n/a |
| Red Hat Data Grid 8 | guava | Not affected | n/a |
| Red Hat Decision Manager 7 | guava | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | guava | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | guava | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | guava | Will not fix | n/a |
| Red Hat Fuse 7 | guava | Will not fix | n/a |
| Red Hat Integration Camel K 1 | guava | Will not fix | n/a |
| Red Hat Integration Camel Quarkus 2 | guava | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | guava | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | guava | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | guava | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | guava | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | guava | Not affected | n/a |
| Red Hat JBoss Fuse 6 | guava | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | guava | Out of support scope | n/a |
| Red Hat JBoss Web Server 5 | guava | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | guava | Out of support scope | n/a |
| Red Hat Process Automation 7 | guava | Out of support scope | n/a |
| Red Hat Satellite 6 | guava | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | guava | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | guava | Affected | n/a |
| Red Hat build of Debezium 1 | guava | Out of support scope | n/a |
| Red Hat build of Debezium 2 | guava | Not affected | n/a |
| Red Hat build of OptaPlanner 8 | guava | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Single Sign-On 7 ships the affected component as a layered product of Red Hat JBoss Enterprise Application 7, and as such is affected by this flaw. However, Single Sign-On 7 does not use the affected code and is not vulnerable to exploit.
Red Hat mitigation
Temp files should be created with sufficiently non-predictable names and in a secure-permissioned, dedicated temp folder.
References (13)
- https://access.redhat.com/security/cve/CVE-2023-2976 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2215229 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1730 Advisory
- https://github.com/advisories/GHSA-7g45-4rm6-3mm3 Advisory
- https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284
- https://github.com/google/guava/issues/2575 Issue TrackingPatchVendor Advisory
- https://github.com/google/guava/issues/6532
- https://github.com/google/guava/releases/tag/v32.0.0
- https://nvd.nist.gov/vuln/detail/CVE-2023-2976
- https://security.netapp.com/advisory/ntap-20230818-0008
- https://security.netapp.com/advisory/ntap-20241108-0002
- https://www.cve.org/CVERecord?id=CVE-2023-2976
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html
Change history (0)
No recorded changes yet.