5.5Medium

Apache Groovy

CVE-2020-17521

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

What this means for your business

  • It affects Apache Groovy. It matters if your company, or a supplier that handles your data, runs it.
  • An attacker can use it only with access to the machine itself, with an ordinary user login, and without anyone at your company clicking anything.

What to do

  1. 1Check whether your company or your suppliers run Apache Groovy, and which version. The affected versions are listed further down this page.
  2. 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.

Not sure if your company is exposed?

Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.

Scoring

CVSS
5.5 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Assigned by
security@apache.org

Dates

Published
2020-12-07
Last modified
2026-08-25
Sources
NVD

Affected products

  • Apache Groovy2.0.0 - 2.4.20, 2.5.0 - 2.5.13, 3.0.0 - 3.0.6, 4.0.0
  • Netapp Snapcenterall versions
  • Oracle Agile Engineering Data Management6.2.1.0
  • Oracle Agile Plm Mcad Connector3.4, 3.6
  • Oracle Agile Product Lifecycle Management9.3.3, 9.3.6
  • Oracle Business Process Management Suite12.2.1.3.0, 12.2.1.4.0
  • Oracle Communications Brm - Elastic Charging Engine11.3.0.9.0, 12.0.0.3
  • Oracle Communications Diameter Signaling Router8.4.0.0
  • Oracle Communications Evolved Communications Application Server7.1
  • Oracle Communications Services Gatekeeper6.0, 6.1, 7.0
  • Oracle Healthcare Data Repository7.0.2
  • Oracle Hospitality Opera 55.6

As listed in the NVD configuration data. Not a statement about your estate.

References