CVE-2020-17521

medium Apache
CVSS v3 Base Score
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.1%
Exploitation probability in 30 days
Top 38% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: December 7, 2020 (2100 days ago)
Last Modified: August 25, 2026
Vendor: Apache
Source: NVD

Description

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

CWE

NVD-CWE-Other

Affected Products

apache groovynetapp snapcenteroracle agile engineering data managementoracle agile plm mcad connectororacle agile product lifecycle managementoracle business process management suiteoracle communications brm - elastic charging engineoracle communications diameter signaling routeroracle communications evolved communications application serveroracle communications services gatekeeper

References