In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kotlin | Jetbrains | 1.4.0-milestone1 (including) | 1.4.0-milestone1 (including) |
Kotlin | Jetbrains | 1.4.0-milestone2 (including) | 1.4.0-milestone2 (including) |
Kotlin | Jetbrains | 1.4.0-milestone3 (including) | 1.4.0-milestone3 (including) |
Kotlin | Jetbrains | 1.4.0-rc (including) | 1.4.0-rc (including) |
Kotlin | Ubuntu | kinetic | * |
Kotlin | Ubuntu | lunar | * |
Kotlin | Ubuntu | mantic | * |
Kotlin | Ubuntu | trusty | * |
Kotlin | Ubuntu | xenial | * |