Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

Project Subscriptions

Vendors Products
Snapcenter Subscribe
Agile Engineering Data Management Subscribe
Agile Plm Subscribe
Agile Plm Mcad Connector Subscribe
Business Process Management Suite Subscribe
Communications Brm - Elastic Charging Engine Subscribe
Communications Diameter Signaling Router Subscribe
Communications Evolved Communications Application Server Subscribe
Communications Services Gatekeeper Subscribe
Healthcare Data Repository Subscribe
Hospitality Opera 5 Subscribe
Ilearning Subscribe
Insurance Policy Administration Subscribe
Jd Edwards Enterpriseone Orchestrator Subscribe
Primavera Gateway Subscribe
Primavera Unifier Subscribe
Retail Bulk Data Integration Subscribe
Retail Merchandising System Subscribe
Retail Store Inventory Management Subscribe
Camel Quarkus Subscribe
Integration Subscribe
Jboss Fuse Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-1505 Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Github GHSA Github GHSA GHSA-rcjj-h6gh-jf3r Information Disclosure in Apache Groovy
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T14:00:48.677Z

Reserved: 2020-08-12T00:00:00

Link: CVE-2020-17521

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-07T20:15:12.633

Modified: 2024-11-21T05:08:16.887

Link: CVE-2020-17521

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-11-19T00:00:00Z

Links: CVE-2020-17521 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses