CVE-2020-29582
published 2021-02-03CVE-2020-29582: In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.57%
83.4th percentile
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kotlin | < kotlin 1.3.31+ds1-3 (forky) | kotlin 1.3.31+ds1-3 (forky) |
| jetbrains | kotlin | < 2.1.0 | 2.1.0 |
| jetbrains | kotlin | >= 0 < 1.3.31+ds1-3 | 1.3.31+ds1-3 |
| jetbrains | kotlin | >= 0 < 1.3.31+ds1-3 | 1.3.31+ds1-3 |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_service_communication_proxy | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) — CVE-2020-29582
vendor_oracle·2022-10-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Kotlin) — CVE-2020-29582
vendor_oracle·2022-04-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (Kotlin) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: Policy (Kotlin) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: SCP (Kotlin) — CVE-2020-29582
vendor_oracle·2022-01-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: SCP (Kotlin) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: SCP (Kotlin) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Calico) — CVE-2020-29582
vendor_oracle·2021-07-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (Calico) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: Signaling (Calico) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure
vendor_redhat·2021-02-03·CVSS 5.3
CVE-2020-29582 [MEDIUM] CWE-276 kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure
kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
Statement: Red Hat CodeReady Studio 12 is not affected by this vulnerability because It ships kotlin-stdlib. The vulnerable component is not in kotlin-stdlib.
Package: kotlin-scripting-jvm (Red Hat Integration Camel Quarkus 1) - Affected
Package: kotlin-scripting-jvm (Red Hat Integration Service Registry) - Not affected
Debian
CVE-2020-29582: kotlin - In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary ...
vendor_debian·2020·CVSS 5.3
CVE-2020-29582 [MEDIUM] CVE-2020-29582: kotlin - In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary ...
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
Scope: local
bookworm: open
forky: resolved (fixed in 1.3.31+ds1-3)
sid: resolved (fixed in 1.3.31+ds1-3)
trixie: resolved (fixed in 1.3.31+ds1-3)
GHSA
Incorrect Default Permissions in JetBrains Kotlin
ghsa·2022-05-24
CVE-2020-29582 [MEDIUM] CWE-276 Incorrect Default Permissions in JetBrains Kotlin
Incorrect Default Permissions in JetBrains Kotlin
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
OSV
Incorrect Default Permissions in JetBrains Kotlin
osv·2022-05-24
CVE-2020-29582 [MEDIUM] Incorrect Default Permissions in JetBrains Kotlin
Incorrect Default Permissions in JetBrains Kotlin
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
OSV
CVE-2020-29582: In JetBrains Kotlin before 1
osv·2021-02-03·CVSS 5.3
CVE-2020-29582 [MEDIUM] CVE-2020-29582: In JetBrains Kotlin before 1
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jetbrains.comhttps://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://blog.jetbrains.comhttps://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe%40%3Cusers.kafka.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-02-03
Published