CVE-2020-29582

EUVD-2022-3613
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
jetbrainskotlin
𝑥
< 1.4.21
oraclecommunications_cloud_native_core_network_slice_selection_function
1.2.1
oraclecommunications_cloud_native_core_policy
1.14.0
oraclecommunications_cloud_native_core_service_communication_proxy
1.14.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
kotlin
bookworm
undetermined
sid
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kotlin
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
ignored
xenial
ignored