CVE编号
CVE-2021-29429利用情况
暂无补丁情况
官方补丁披露时间
2021-04-13漏洞描述
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system temporary directory first. Sensitive information contained in these files can be exposed to other local users on the same system. If you do not use the `TextResourceFactory` API, you are not vulnerable. As of Gradle 7.0, uses of the system temporary directory have been moved to the Gradle User Home directory. By default, this directory is restricted to the user running the build. As a workaround, set a more restrictive umask that removes read access to other users. When files are created in the system temporary directory, they will not be accessible to other users. If you are unable to change your system's umask, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only.解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
https://docs.gradle.org/7.0/release-notes.html#security-advisories | |
https://github.com/gradle/gradle/security/advisories/GHSA-fp8h-qmr5-j4c8 |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | gradle | gradle | * |
Up to (excluding) 7.0 |
|||||
运行在以下环境 | |||||||||
系统 | debian_10 | gradle | * |
Up to (excluding) 4.4.1-6 |
|||||
运行在以下环境 | |||||||||
系统 | debian_11 | gradle | * |
Up to (excluding) 4.4.1-13 |
|||||
运行在以下环境 | |||||||||
系统 | debian_12 | gradle | * |
Up to (excluding) 4.4.1-13 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | gradle | * |
Up to (excluding) 3.2.1-1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_sid | gradle | * |
Up to (excluding) 4.4.1-13 |
|||||
- 攻击路径 本地
- 攻击复杂度 复杂
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 N/A
- 补丁情况 官方补丁
- 数据保密性 N/A
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 N/A
还没有评论,来说两句吧...