Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Guava Dependancy is vulnerable to insecure use of temporary directory #8811

Open
Marinofull opened this issue Feb 9, 2024 · 0 comments
Open

Comments

@Marinofull
Copy link

###Description

GHSA-7g45-4rm6-3mm3 reports a Guava temporary directory usage vulnerability, and Guava less than 32 is affected by this vulnerability. It is Moderate priority, I made a research and found that this patch was reverted last year (#8547) due to gradle incompatibility, but now robolectric uses the newest gradle, so it should work I think.

###Steps to Reproduce

See https://deps.dev/maven/org.robolectric%3Arobolectric/4.11.1 and https://deps.dev/advisory/osv/GHSA-7g45-4rm6-3mm3.

###Robolectric & Android Version

4.11.1 and current master branch.

###Link to a public git repo demonstrating the problem:

Robolectric itself.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant