PT-2021-10101 · Unknown+1 · Html/Java Api+1

Published

2021-01-11

·

Updated

2022-02-09

·

CVE-2020-17534

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: HTML/Java API versions 1.7 through 1.7
Description: There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in the webkit subproject. A similar issue has been disclosed in other Java projects. The fix creates the temporary directory atomically without dealing with the temporary file to avoid local privilege escalation.
Recommendations: For HTML/Java API versions 1.7 through 1.7, update to version 1.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the webkit subproject until the update is applied.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17534
GHSA-PPC3-FPVH-7396

Affected Products

Html/Java Api
Webkit