5.5mediumMedium
CVE-2020-17521
Apache Groovy
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 5.5 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N- Assigned by
- security@apache.org
Dates
- Published
- 2020-12-07
- Last modified
- 2026-08-25
- Sources
- NVD
Affected products
- Apache Groovy2.0.0 - 2.4.20, 2.5.0 - 2.5.13, 3.0.0 - 3.0.6, 4.0.0
- Netapp Snapcenterall versions
- Oracle Agile Engineering Data Management6.2.1.0
- Oracle Agile Plm Mcad Connector3.4, 3.6
- Oracle Agile Product Lifecycle Management9.3.3, 9.3.6
- Oracle Business Process Management Suite12.2.1.3.0, 12.2.1.4.0
- Oracle Communications Brm - Elastic Charging Engine11.3.0.9.0, 12.0.0.3
- Oracle Communications Diameter Signaling Router8.4.0.0
- Oracle Communications Evolved Communications Application Server7.1
- Oracle Communications Services Gatekeeper6.0, 6.1, 7.0
- Oracle Healthcare Data Repository7.0.2
- Oracle Hospitality Opera 55.6
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://groovy-lang.org/security.html#CVE-2020-17521
- https://lists.apache.org/thread.html/r4b2f13c302eec98838ff7475253091fb9b75bc1038016ba00ebf6c08%40%3Cdev.atlas.apache.org%3E
- https://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3E
- https://lists.apache.org/thread.html/rea63a4666ba245d2892471307772a2d8ce0f0741f341d6576625c1b3%40%3Cdev.atlas.apache.org%3E
- https://security.netapp.com/advisory/ntap-20201218-0006/
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://groovy-lang.org/security.html#CVE-2020-17521
- https://lists.apache.org/thread.html/r4b2f13c302eec98838ff7475253091fb9b75bc1038016ba00ebf6c08%40%3Cdev.atlas.apache.org%3E
- https://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3E