Incorrect permission assignment for critical resource in gradle - CVE-2023-44387
Published: December 7, 2023
Vulnerability identifier: #VU83979
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44387
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the way Gradle sets permissions when copying or archiving symlinked files. A local user can set permissions on the symlinks that will be applied to the linked files.
Affected software
gradle
AMQ Streams
Siebel CRM End User
AMQ Streams
Siebel CRM End User
How to mitigate CVE-2023-44387
Install updates from vendor's website.
gradle - addressed in versions 7.6.3, 8.4.0
AMQ Streams - update to 2.6.0
AMQ Streams - update to 2.6.0
External References
- https://github.com/gradle/gradle/security/advisories/GHSA-43r3-pqhv-f7h9
- https://github.com/gradle/gradle/releases/tag/v7.6.3
- https://github.com/gradle/gradle/releases/tag/v8.4.0
- https://github.com/gradle/gradle/commit/3b406191e24d69e7e42dc3f3b5cc50625aa930b7
- https://security.netapp.com/advisory/ntap-20231110-0006/