CVE-2020-17521
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Published:Nov 19, 2020
Last Modified:Aug 25, 2026
EPS:Dec 7, 2020
EPSS Score:0.0105
CVSS Score:5.5
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Atlas
Apache
Atlas
Vendor
Apache
Product
Groovy
Apache
Groovy
Vendor
Netapp
Product
Snapcenter
Netapp
Snapcenter
Vendor
Oracle
Product
Agile Engineering Data Management
Oracle
Agile Engineering Data Management
Vendor
Oracle
Product
Agile Plm Mcad Connector
Oracle
Agile Plm Mcad Connector
Vendor
Oracle
Product
Agile Product Lifecycle Management
Oracle
Agile Product Lifecycle Management
Vendor
Oracle
Product
Business Process Management Suite
Oracle
Business Process Management Suite
Vendor
Oracle
Product
Communications Brm - Elastic Charging Engine
Oracle
Communications Brm - Elastic Charging Engine
Vendor
Oracle
Product
Communications Diameter Signaling Router
Oracle
Communications Diameter Signaling Router
Vendor
Oracle
Product
Communications Evolved Communications Application Server
Oracle
Communications Evolved Communications Application Server
Vendor
Oracle
Product
Communications Services Gatekeeper
Oracle
Communications Services Gatekeeper
Vendor
Oracle
Product
Healthcare Data Repository
Oracle
Healthcare Data Repository
Vendor
Oracle
Product
Hospitality Opera 5
Oracle
Hospitality Opera 5
Vendor
Oracle
Product
Ilearning
Oracle
Ilearning
Vendor
Oracle
Product
Insurance Policy Administration
Oracle
Insurance Policy Administration
Vendor
Oracle
Product
Jd Edwards Enterpriseone Orchestrator
Oracle
Jd Edwards Enterpriseone Orchestrator
Vendor
Oracle
Product
Primavera Gateway
Oracle
Primavera Gateway
Vendor
Oracle
Product
Primavera Unifier
Oracle
Primavera Unifier
Vendor
Oracle
Product
Retail Bulk Data Integration
Oracle
Retail Bulk Data Integration
Vendor
Oracle
Product
Retail Merchandising System
Oracle
Retail Merchandising System
Vendor
Oracle
Product
Retail Store Inventory Management
Oracle
Retail Store Inventory Management
Vendor
Redhat
Product
Camel Quarkus
Redhat
Camel Quarkus
Vendor
Redhat
Product
Integration
Redhat
Integration
Vendor
Redhat
Product
Jboss Fuse
Redhat
Jboss Fuse
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
