Creation of Temporary File With Insecure Permissions in gradle - CVE-2021-29428

 

Creation of Temporary File With Insecure Permissions in gradle - CVE-2021-29428

Published: May 20, 2022 / Updated: May 20, 2022


Vulnerability identifier: #VU63476
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29428
CWE-ID: CWE-378
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to quickly deleting and recreating files in the system temporary directory. A local user can gain elevated privileges on the target system.


Affected software

gradle
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Development Tools Module
openSUSE Leap
gradle

How to mitigate CVE-2021-29428

Install updates from vendor's website.

gradle - update to 7.0.0
gradle - update to 4.4.1-150200.3.7.1

External References

Related Security Bulletins