In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:jetbrains:kotlin:1.4.0:milestone3:*:*:*:*:*:*"
],
"vendor_product": "jetbrains:kotlin",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "1.4.0-milestone3"
},
{
"last_affected": "1.4.0-milestone3"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:banking_extensibility_workbench:14.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_extensibility_workbench:14.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_extensibility_workbench:14.5:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_extensibility_workbench",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "14.2"
},
{
"last_affected": "14.2"
},
{
"introduced": "14.3"
},
{
"last_affected": "14.3"
},
{
"introduced": "14.5"
},
{
"last_affected": "14.5"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_cloud_native_core_policy",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "1.14.0"
},
{
"last_affected": "1.14.0"
}
]
}
]
}{
"cpe": [
"cpe:2.3:a:jetbrains:kotlin:1.4.0:milestone1:*:*:*:*:*:*",
"cpe:2.3:a:jetbrains:kotlin:1.4.0:milestone2:*:*:*:*:*:*",
"cpe:2.3:a:jetbrains:kotlin:1.4.0:rc:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "1.4.0-milestone1"
},
{
"last_affected": "1.4.0-milestone1"
},
{
"introduced": "1.4.0-milestone2"
},
{
"last_affected": "1.4.0-milestone2"
},
{
"introduced": "1.4.0-rc"
},
{
"last_affected": "1.4.0-rc"
}
]
}