PT-2021-15440 · Square · Com.Squareup:Connect
Jonathan Leitschuh
·
Published
2021-02-03
·
Updated
2022-04-08
·
CVE-2021-23331
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
com.squareup:connect (affected versions not specified)
Description
The issue affects the prepareDownloadFile method, which creates a temporary file with permissions bits of -rw-r--r-- on unix-like systems. Since the system temporary directory is shared between users, the contents of the downloaded file will be visible to all other users on the local system.
Recommendations
For all affected versions, set the system property java.io.tmpdir to a safe directory as a workaround.
It is also recommended to upgrade to the latest version of the SDK, as the current version is end of life and no longer maintained.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Com.Squareup:Connect