Back

HIGH

Use of temporary directory for file creation in `FileBackedOutputStream` in Guava

Published Jun 14, 2023

Description

Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.

Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.

Affected products

Remediation

Red Hat statement

Red Hat Single Sign-On 7 ships the affected component as a layered product of Red Hat JBoss Enterprise Application 7, and as such is affected by this flaw. However, Single Sign-On 7 does not use the affected code and is not vulnerable to exploit.

Red Hat mitigation

Temp files should be created with sufficiently non-predictable names and in a secure-permissioned, dedicated temp folder.

Weaknesses (2)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Jun 14, 2023
Updated Feb 25, 2026
Reserved May 30, 2023
CISA Vulnrichment
Updated Apr 18, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 14, 2023
ENISA EUVD
Assigner Google
Published Jun 14, 2023
Updated Feb 25, 2026
Exploited since n/a
EUVD-2023-1730 GHSA-7G45-4RM6-3MM3