Lucene search

K
redosRedosROS-20240507-03
HistoryMay 07, 2024 - 12:00 a.m.

ROS-20240507-03

2024-05-0700:00:00
redos.red-soft.ru
17
vulnerability
google guava
java library
filebackedoutputstream
unauthorized access
protected information

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

15.5%

A vulnerability in the FileBackedOutputStream feature of the Google Guava Java library suite is related to the use of
files and directories accessible to external parties. Exploitation of the vulnerability could allow an attacker to
Gain unauthorized access to protected information

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64guava<ย 32.1.2-2UNKNOWN

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

15.5%