CVE-2020-29582

MEDIUM

JetBrains Kotlin <1.4.21 - Info Disclosure

Title source: llm
STIX 2.1

Description

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

References (6)

Core 6
Core References
Vendor Advisory x_refsource_misc
https://blog.jetbrains.com
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 5.3
EPSS 0.0000
EPSS Percentile 0.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-276
Status published
Products (5)
jetbrains/kotlin < 1.4.21
oracle/communications_cloud_native_core_network_slice_selection_function 1.2.1
oracle/communications_cloud_native_core_policy 1.14.0
oracle/communications_cloud_native_core_service_communication_proxy 1.14.0
org.jetbrains.kotlin/kotlin-stdlib 0 - 1.4.21Maven
Published Feb 03, 2021
Tracked Since Feb 18, 2026