In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
{ "binaries": [ { "binary_version": "1.3.31+~1.0.1+~0.11.12-2", "binary_name": "kotlin" } ] }
{ "binaries": [ { "binary_version": "1.3.31+ds1-1ubuntu1", "binary_name": "kotlin" } ] }
{ "binaries": [ { "binary_version": "1.3.31+ds1-2", "binary_name": "kotlin" } ] }