Insecure Temporary File in gradle - CVE-2021-29429

 

Insecure Temporary File in gradle - CVE-2021-29429

Published: May 20, 2022 / Updated: May 20, 2022


Vulnerability identifier: #VU63478
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29429
CWE-ID: CWE-377
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to remote files accessed through TextResourceFactory being downloaded into the system temporary directory first. A local user with access to the system can view contents of files and gain access to sensitive information.


Affected software

gradle
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Development Tools Module
openSUSE Leap
gpars-bootstrap
groovy-bootstrap
gradle-bootstrap
gradle

How to mitigate CVE-2021-29429

Install updates from vendor's website.

gradle - update to 7.0.0
gpars-bootstrap - update to 1.2.1-150200.3.9.1
groovy-bootstrap - update to 2.4.21-150200.3.9.1
gradle-bootstrap - update to 4.4.1-150200.3.9.1
gradle - update to 4.4.1-150200.3.15.1

External References

Related Security Bulletins