cbcvebase.
CVE-2023-2976
published 2023-06-14

CVE-2023-2976: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice…

PriorityP433high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.25%
16.0th percentile
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.

Affected

10 ranges
VendorProductVersion rangeFixed in
atlassianjira_service_management
debianguava-libraries< guava-libraries 32.0.1-1 (forky)guava-libraries 32.0.1-1 (forky)
googleguava< 32.0.032.0.0
googleguava>= 1.0 < 32.0.032.0.0
msrcazl3_javapackages-bootstrap_1.14.0-3_on_azure_linux_3.0
msrccbl2_guava_25.0-8_on_cbl_mariner_2.0
msrccbl2_javapackages-bootstrap_1.5.0-5_on_cbl_mariner_2.0
msrccbl2_maven_3.8.7-3_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv7.1HIGH
vendor_oracle7.1MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.