CVE-2023-2976
published 2023-06-14CVE-2023-2976: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice…
PriorityP433high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.25%
16.0th percentile
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | jira_service_management | — | — |
| debian | guava-libraries | < guava-libraries 32.0.1-1 (forky) | guava-libraries 32.0.1-1 (forky) |
| guava | < 32.0.0 | 32.0.0 | |
| guava | >= 1.0 < 32.0.0 | 32.0.0 | |
| msrc | azl3_javapackages-bootstrap_1.14.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_guava_25.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_javapackages-bootstrap_1.5.0-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_maven_3.8.7-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv7.1HIGH
vendor_oracle7.1MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Insurance Applications Risk Matrix: EWPS (Google Guava) — CVE-2023-2976
vendor_oracle·2025-10-15·CVSS 7.1
CVE-2023-2976 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: EWPS (Google Guava) — CVE-2023-2976
Oracle Oracle Insurance Applications Risk Matrix: EWPS (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle JD Edwards Risk Matrix: Monitoring and Diagnostics SEC (Google Guava) — CVE-2023-2976
vendor_oracle·2025-01-15·CVSS 7.1
CVE-2023-2976 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Monitoring and Diagnostics SEC (Google Guava) — CVE-2023-2976
Oracle Oracle JD Edwards Risk Matrix: Monitoring and Diagnostics SEC (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: Blockchain Cloud Service Console (Google Guava) — CVE-2023-2976
vendor_oracle·2024-10-15·CVSS 6.0
CVE-2023-2976 [MEDIUM] Oracle Oracle Blockchain Platform Risk Matrix: Blockchain Cloud Service Console (Google Guava) — CVE-2023-2976
Oracle Oracle Blockchain Platform Risk Matrix: Blockchain Cloud Service Console (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 6.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer (Google Guava) — CVE-2023-2976
vendor_oracle·2024-07-15·CVSS 7.1
CVE-2023-2976 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer (Google Guava) — CVE-2023-2976
Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Google Guava) — CVE-2023-2976
vendor_oracle·2024-04-15·CVSS 7.1
CVE-2023-2976 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Google Guava) — CVE-2023-2976
Oracle Oracle Commerce Risk Matrix: Content Acquisition System, Workbench (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2024 (APR 2024)
Atlassian
CVE-2023-2976: 5.13.0 from 5.12.0 (LTS) to 5.12.2 (LTS) from 5.11.0 to 5.11.3 from 5.10.0 to 5.10.2 from 5.9.0 to 5.9.2 from 5.8.0 to 5
vendor_atlassian·2024-02-20·CVSS 5.1
CVE-2023-2976 [MEDIUM] CVE-2023-2976: 5.13.0 from 5.12.0 (LTS) to 5.12.2 (LTS) from 5.11.0 to 5.11.3 from 5.10.0 to 5.10.2 from 5.9.0 to 5.9.2 from 5.8.0 to 5
CVE-2023-2976: 5.13.0 from 5.12.0 (LTS) to 5.12.2 (LTS) from 5.11.0 to 5.11.3 from 5.10.0 to 5.10.2 from 5.9.0 to 5.9.2 from 5.8.0 to 5
5.13.0 from 5.12.0 (LTS) to 5.12.2 (LTS) from 5.11.0 to 5.11.3 from 5.10.0 to 5.10.2 from 5.9.0 to 5.9.2 from 5.8.0 to 5.8.2 from 5.7.0 to 5.7.2 from 5.6.0 to 5.6.2 from 5.5.0 to 5.5.1 from 5.4.0 (LTS) to 5.4.15 (LTS) from 5.3.0 to 5.3.1 from 5.2.0 to 5.2.1 from 5.1.0 to 5.1.1 5.0 from 4.22.0 to 4.22.6 Any earlier versions
CVE: CVE-2023-2976
Affected products: Jira Service Management
Oracle
Oracle Oracle Communications Applications Risk Matrix: Charging (Google Guava) — CVE-2023-2976
vendor_oracle·2024-01-15·CVSS 7.1
CVE-2023-2976 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Charging (Google Guava) — CVE-2023-2976
Oracle Oracle Communications Applications Risk Matrix: Charging (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Google Guava) — CVE-2023-2976
vendor_oracle·2023-10-15·CVSS 7.1
CVE-2023-2976 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Google Guava) — CVE-2023-2976
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Google Guava) vulnerability
CVE: CVE-2023-2976
CVSS: 7.1
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2023 (OCT 2023)
Red Hat
guava: insecure temporary directory creation
vendor_redhat·2023-06-14·CVSS 5.5
CVE-2023-2976 [MEDIUM] CWE-552 guava: insecure temporary directory creation
guava: insecure temporary directory creation
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
A flaw was found in Guava. The methodology for temporary directories and files can allow other local users or apps with accordant permissions to access the temp files, possibly leading to information exposure or tampering in the files created in the directory.
Statement:
Microsoft
Use of temporary directory for file creation in `FileBackedOutputStream` in Guava
vendor_msrc·2023-06-13·CVSS 5.5
CVE-2023-2976 [MEDIUM] CWE-552 Use of temporary directory for file creation in `FileBackedOutputStream` in Guava
Use of temporary directory for file creation in `FileBackedOutputStream` in Guava
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Google: Google
Customer Action Required: Yes
Remediation: CBL-Mariner Releas
Debian
CVE-2023-2976: guava-libraries - Use of Java's default temporary directory for file creation in `FileBackedOutput...
vendor_debian·2023·CVSS 5.5
CVE-2023-2976 [MEDIUM] CVE-2023-2976: guava-libraries - Use of Java's default temporary directory for file creation in `FileBackedOutput...
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 32.0.1-1)
sid: resolved (fixed in 32.0.1-1)
trixie: resolved (fixed in 32.0.1-1)
OSV
CVE-2023-2976: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1
osv·2023-06-14·CVSS 7.1
CVE-2023-2976 [HIGH] CVE-2023-2976: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class. Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
OSV
Guava vulnerable to insecure use of temporary directory
osv·2023-06-14
CVE-2023-2976 [MEDIUM] Guava vulnerable to insecure use of temporary directory
Guava vulnerable to insecure use of temporary directory
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
GHSA
Guava vulnerable to insecure use of temporary directory
ghsa·2023-06-14
CVE-2023-2976 [MEDIUM] CWE-379 Guava vulnerable to insecure use of temporary directory
Guava vulnerable to insecure use of temporary directory
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
No detection rules found.
No public exploits indexed.
https://github.com/google/guava/issues/2575https://security.netapp.com/advisory/ntap-20230818-0008/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.htmlhttps://github.com/google/guava/issues/2575https://security.netapp.com/advisory/ntap-20230818-0008/https://security.netapp.com/advisory/ntap-20241108-0002/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html
2023-06-14
Published