In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.4.0-milestone1"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.0-milestone2"
},
{
"introduced": "0"
},
{
"last_affected": "1.4.0-rc"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.4.0-milestone3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15824.json"