imPC@ndo IT

Tracker / CVE-2020-17521

CVE-2020-17521

Medium 5.5

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

Affected products and versions

apache atlas
apache groovy
apache groovy · 2.0.0 → 2.4.20
apache groovy · 2.5.0 → 2.5.13
apache groovy · 3.0.0 → 3.0.6
netapp snapcenter
oracle agile_engineering_data_management
oracle agile_plm
oracle agile_plm_mcad_connector
oracle business_process_management_suite
oracle communications_brm_-_elastic_charging_engine
oracle communications_diameter_signaling_router
oracle communications_evolved_communications_application_server
oracle communications_services_gatekeeper
oracle healthcare_data_repository
oracle hospitality_opera_5
oracle ilearning
oracle insurance_policy_administration · 11.0 → 11.3.1
oracle jd_edwards_enterpriseone_orchestrator
oracle primavera_gateway · 17.12.0 → 17.12.10
oracle primavera_unifier
oracle primavera_unifier · 17.7 → 17.12
oracle retail_bulk_data_integration
oracle retail_merchandising_system
oracle retail_store_inventory_management

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References