CVE-2020-29582Incorrect Default Permissions in Kotlin

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 99.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateOct 15

Description

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Patches

🔴Vulnerability Details

4
GHSA
Incorrect Default Permissions in JetBrains Kotlin2022-05-24
OSV
Incorrect Default Permissions in JetBrains Kotlin2022-05-24
OSV
CVE-2020-29582: In JetBrains Kotlin before 12021-02-03
CVEList
CVE-2020-29582: In JetBrains Kotlin before 12021-02-03

📋Vendor Advisories

6
Oracle
Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) — CVE-2020-295822022-10-15
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Kotlin) — CVE-2020-295822022-04-15
Oracle
Oracle Oracle Communications Risk Matrix: SCP (Kotlin) — CVE-2020-295822022-01-15
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Calico) — CVE-2020-295822021-07-15
Red Hat
kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure2021-02-03
CVE-2020-29582 — Incorrect Default Permissions | cvebase