HIGHMaven →
Guava vulnerable to insecure use of temporary directory
Guava vulnerable to insecure use of temporary directory
Affected packages
- com.google.guava:guava— 1.0 → 32.0.0-android
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2023-2976
- https://github.com/google/guava/issues/2575
- https://github.com/google/guava/issues/6532
- https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284
- https://github.com/google/guava
- https://github.com/google/guava/releases/tag/v32.0.0
- https://security.netapp.com/advisory/ntap-20230818-0008
- https://security.netapp.com/advisory/ntap-20241108-0002
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html
Structured record: https://osv.dev/vulnerability/GHSA-7g45-4rm6-3mm3
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta