VYPR
High severity7.8NVD Advisory· Published Nov 15, 2017· Updated May 13, 2026

CVE-2017-15288

CVE-2017-15288

Description

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.scala-lang:scala-compilerMaven
< 2.10.72.10.7
org.scala-lang:scala-compilerMaven
>= 2.11.0, < 2.11.122.11.12
org.scala-lang:scala-compilerMaven
>= 2.12.0, < 2.12.42.12.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

35

News mentions

0

No linked articles in our index yet.