VYPR
Medium severity5.5NVD Advisory· Published Mar 29, 2022· Updated Jun 17, 2026

CVE-2021-22572

CVE-2021-22572

Description

On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary directory with world readable permissions. Any sensitive information written to theses files is visible to all other local users on unix-like systems. We recommend upgrading past commit https://github.com/google/data-transfer-project/pull/969

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Google LLC/Data-Transfer-Projectv5
    Range: unspecified
  • cpe:2.3:a:google:data_transfer_project:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:google:data_transfer_project:*:*:*:*:*:*:*:*range: <0.3.57
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.