CVE-2020-17534

HIGH

HTML/Java API <1.7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local privilege escalation version 1.7.1 creates the temporary directory atomically without dealing with the temporary file: https://github.com/apache/netbeans-html4j/commit/fa70e507e5555e1adb4f6518479fc408a7abd0e6

References (1)

Core 1

Scores

CVSS v3 7.0
EPSS 0.0007
EPSS Percentile 20.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (2)
apache/html\/java_api 1.7
org.netbeans.html/pom 0 - 1.7.1Maven
Published Jan 11, 2021
Tracked Since Feb 18, 2026