PT-2021-10101 · Unknown+1 · Html/Java Api+1
Published
2021-01-11
·
Updated
2022-02-09
·
CVE-2020-17534
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
HTML/Java API versions 1.7 through 1.7
Description:
There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in the
webkit subproject. A similar issue has been disclosed in other Java projects. The fix creates the temporary directory atomically without dealing with the temporary file to avoid local privilege escalation.Recommendations:
For HTML/Java API versions 1.7 through 1.7, update to version 1.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the
webkit subproject until the update is applied.Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Html/Java Api
Webkit