PT-2021-15440 · Square · Com.Squareup:Connect

Jonathan Leitschuh

·

Published

2021-02-03

·

Updated

2022-04-08

·

CVE-2021-23331

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions com.squareup:connect (affected versions not specified)
Description The issue affects the prepareDownloadFile method, which creates a temporary file with permissions bits of -rw-r--r-- on unix-like systems. Since the system temporary directory is shared between users, the contents of the downloaded file will be visible to all other users on the local system.
Recommendations For all affected versions, set the system property java.io.tmpdir to a safe directory as a workaround. It is also recommended to upgrade to the latest version of the SDK, as the current version is end of life and no longer maintained.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23331
GHSA-Q4HM-FWC9-HMV6
SNYK-JAVA-COMSQUAREUP-1065988

Affected Products

Com.Squareup:Connect