Uploaded image for project: 'Qpid'
  1. Qpid
  2. QPID-8485

Upgrade guava version to latest

    XMLWordPrintableJSON

Details

    • Task
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • None
    • qpid-java-broker-8.0.3
    • Broker-J
    • None

    Description

      Security vulnerabilities are reported with the guava version below 28.2-jre.

      This package are vulnerable to Information Disclosure. The file permissions on the file created by com.google.common.io.Files.createTempDir allows an attacker running a malicious program co-resident on the same machine can steal secrets stored in this directory. This is because by default on unix-like operating systems the /temp directory is shared between all users, so if the correct file permissions aren't set by the directory/file creator, the file becomes readable by all other users on that system.

      https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415

      The Qpid Broker does not utilize the impacted functionality. Thus, it is not vulnerable to the reported issue. Though, we need to upgrade the guava version in order to stop from being flagged by scanning tools

      Attachments

        Activity

          People

            Unassigned Unassigned
            DedeepyaT Dedeepya
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: