Description
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Published: 2020-12-07
Score: 5.5 Medium
EPSS: 2.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-1505 Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Github GHSA Github GHSA GHSA-rcjj-h6gh-jf3r Information Disclosure in Apache Groovy
History

No history.

Subscriptions

Apache Atlas Groovy
Netapp Snapcenter
Oracle Agile Engineering Data Management Agile Plm Agile Plm Mcad Connector Business Process Management Suite Communications Brm - Elastic Charging Engine Communications Diameter Signaling Router Communications Evolved Communications Application Server Communications Services Gatekeeper Healthcare Data Repository Hospitality Opera 5 Ilearning Insurance Policy Administration Jd Edwards Enterpriseone Orchestrator Primavera Gateway Primavera Unifier Retail Bulk Data Integration Retail Merchandising System Retail Store Inventory Management
Redhat Camel Quarkus Integration Jboss Fuse
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T14:00:48.677Z

Reserved: 2020-08-12T00:00:00.000Z

Link: CVE-2020-17521

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-07T20:15:12.633

Modified: 2024-11-21T05:08:16.887

Link: CVE-2020-17521

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-11-19T00:00:00Z

Links: CVE-2020-17521 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses