SCA: security update for com.datadoghq:datadog-api-client (GHSA-2cxf-6567-7pp6)

low Tenable Self-Hosted Container Security Plugin ID 408874

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of
sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-
like system with multiple users. The API is used to download a file containing sensitive information. This
sensitive information is exposed locally to other users. This vulnerability exists in the API Client for
version 1 and 2. The method `prepareDownloadFilecreates` creates a temporary file with the permissions
bits of `-rw-r--r--` on unix-like systems. On unix-like systems, the system temporary directory is shared
between users. As such, the contents of the file downloaded via the `downloadFileFromResponse` method will
be visible to all other users on the local system. Analysis of the finding determined that the affected
code was unused, meaning that the exploitation likelihood is low. The unused code has been removed,
effectively mitigating this issue. This issue has been patched in version 1.0.0-beta.9. As a workaround
one may specify `java.io.tmpdir` when starting the JVM with the flag `-Djava.io.tmpdir`, specifying a path
to a directory with `drw-------` permissions owned by `dd-agent`. (CVE-2021-21331)

See Also

https://github.com/advisories/GHSA-2cxf-6567-7pp6

Plugin Details

Severity: Low

ID: 408874

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.2

Percentile: 50.81

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2021-21331

CVSS v3

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/3/2021

Vulnerability Publication Date: 3/3/2021

Reference Information

CVE: CVE-2021-21331