In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
2021-02-03T16:15:13.727
2024-11-21T05:24:15.503
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jetbrains | kotlin | < 1.4.21 | Yes |
Application | oracle | communications_cloud_native_core_network_slice_selection_function | 1.2.1 | Yes |
Application | oracle | communications_cloud_native_core_policy | 1.14.0 | Yes |
Application | oracle | communications_cloud_native_core_service_communication_proxy | 1.14.0 | Yes |