Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Nov 21, 2023 |
| Debian | — | Upgrade guava-librariesNo solution exists | May 15, 2025 | Jun 14, 2023 |
| Dell Powerstore Dsa2024158 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2024 |
| Dell Powerstore Dsa2024225 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 29, 2024 |
| Dell Powerstore Dsa2024287 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jul 2, 2024 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 36454290 for version 14.1.1.0.0. | Oct 19, 2023 | Jun 14, 2023 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jun 14, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 14, 2023 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.1.5Upgrade Splunk Enterprise to version 9.2.2Upgrade Splunk Enterprise to version 9.0.10 | Sep 30, 2025 | Jun 14, 2023 |
| Suse | — | Upgrade guava-javadocUpgrade guavaUpgrade guava-testlib | Aug 2, 2023 | Jun 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub