CVE-2020-17521
published 2020-12-07CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
1.05%
60.4th percentile
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | atlas | — | — |
| apache | groovy | — | — |
| apache | groovy | >= 0 < 2.4.21-1 | 2.4.21-1 |
| apache | groovy | >= 0 < 2.4.21-1 | 2.4.21-1 |
| apache | groovy | >= 0 < 2.4.21-1 | 2.4.21-1 |
| apache | groovy | >= 0 < 2.4.21-1 | 2.4.21-1 |
| apache | groovy | 2.0.0 – 2.4.20 | — |
| apache | groovy | 2.5.0 – 2.5.13 | — |
| apache | groovy | 3.0.0 – 3.0.6 | — |
| apache_software_foundation | apache_groovy | — | — |
| apache_software_foundation | apache_groovy | — | — |
| apache_software_foundation | apache_groovy | — | — |
| apache_software_foundation | apache_groovy | — | — |
| debian | groovy | < groovy 2.4.21-1 (bookworm) | groovy 2.4.21-1 (bookworm) |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm_mcad_connector | — | — |
| oracle | agile_plm_mcad_connector | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | communications_brm_elastic_charging_engine | — | — |
| oracle | communications_brm_elastic_charging_engine | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_evolved_communications_application_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Information Disclosure in Apache Groovy
ghsa·2020-12-09
CVE-2020-17521 [MEDIUM] CWE-379 Information Disclosure in Apache Groovy
Information Disclosure in Apache Groovy
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
OSV
Information Disclosure in Apache Groovy
osv·2020-12-09
CVE-2020-17521 [MEDIUM] Information Disclosure in Apache Groovy
Information Disclosure in Apache Groovy
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
OSV
CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories
osv·2020-12-07·CVSS 5.5
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Oracle
Oracle Oracle Systems Risk Matrix: Core (Apache Groovy) — CVE-2020-17521
vendor_oracle·2025-10-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Systems Risk Matrix: Core (Apache Groovy) — CVE-2020-17521
Oracle Oracle Systems Risk Matrix: Core (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Connectors and Connector Server (Apache Groovy) — CVE-2020-17521
vendor_oracle·2024-10-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Connectors and Connector Server (Apache Groovy) — CVE-2020-17521
Oracle Oracle Fusion Middleware Risk Matrix: Connectors and Connector Server (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Groovy) — CVE-2020-17521
vendor_oracle·2023-07-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Groovy) — CVE-2020-17521
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle iLearning Risk Matrix: Installation (Apache Groovy) — CVE-2020-17521
vendor_oracle·2023-04-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle iLearning Risk Matrix: Installation (Apache Groovy) — CVE-2020-17521
Oracle Oracle iLearning Risk Matrix: Installation (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Apache Groovy) — CVE-2020-17521
vendor_oracle·2022-10-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Apache Groovy) — CVE-2020-17521
Oracle Oracle Fusion Middleware Risk Matrix: Runtime Java agent for ODI (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Supply Chain Risk Matrix: Installation Issues (Apache Groovy) — CVE-2020-17521
vendor_oracle·2022-07-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: Installation Issues (Apache Groovy) — CVE-2020-17521
Oracle Oracle Supply Chain Risk Matrix: Installation Issues (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: API Gateway (Apache Groovy) — CVE-2020-17521
vendor_oracle·2022-04-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Communications Risk Matrix: API Gateway (Apache Groovy) — CVE-2020-17521
Oracle Oracle Communications Risk Matrix: API Gateway (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Supply Chain Risk Matrix: CAX Client (Apache Groovy) — CVE-2020-17521
vendor_oracle·2022-01-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: CAX Client (Apache Groovy) — CVE-2020-17521
Oracle Oracle Supply Chain Risk Matrix: CAX Client (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Orchestration (Apache Groovy) — CVE-2020-17521
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Orchestration (Apache Groovy) — CVE-2020-17521
Oracle Oracle Communications Applications Risk Matrix: Orchestration (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Elastic charging controller (Apache Groovy) — CVE-2020-17521
vendor_oracle·2021-07-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Elastic charging controller (Apache Groovy) — CVE-2020-17521
Oracle Oracle Communications Applications Risk Matrix: Elastic charging controller (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Risk Matrix: PRM (Apache Groovy) — CVE-2020-17521
vendor_oracle·2021-04-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Communications Risk Matrix: PRM (Apache Groovy) — CVE-2020-17521
Oracle Oracle Communications Risk Matrix: PRM (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Retail Applications Risk Matrix: BDI Job Scheduler (Apache Groovy) — CVE-2020-17521
vendor_oracle·2021-01-15·CVSS 5.5
CVE-2020-17521 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: BDI Job Scheduler (Apache Groovy) — CVE-2020-17521
Oracle Oracle Retail Applications Risk Matrix: BDI Job Scheduler (Apache Groovy) vulnerability
CVE: CVE-2020-17521
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2021 (JAN 2021)
Red Hat
groovy: OS temporary directory leads to information disclosure
vendor_redhat·2020-11-19·CVSS 5.5
CVE-2020-17521 [MEDIUM] CWE-200 groovy: OS temporary directory leads to information disclosure
groovy: OS temporary directory leads to information disclosure
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
A flaw was found in Apache Groovy. Groovy makes use of a method for creating temporary directories which is not suitable for security-sensitive contexts and allows for sensitive
Debian
CVE-2020-17521: groovy - Apache Groovy provides extension methods to aid with creating temporary director...
vendor_debian·2020·CVSS 5.5
CVE-2020-17521 [MEDIUM] CVE-2020-17521: groovy - Apache Groovy provides extension methods to aid with creating temporary director...
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Scope: local
bookworm: resolved (fixed in 2.4.21-1)
bullseye: resolved (fixed in 2.4.21-1)
forky: resolved (fixed in 2.4.21-1)
sid: resolved (fixed in 2.4.21-1)
trixie: resolved (fixed in 2.4.21-1)
No detection rules found.
No public exploits indexed.
https://groovy-lang.org/security.html#CVE-2020-17521https://lists.apache.org/thread.html/r4b2f13c302eec98838ff7475253091fb9b75bc1038016ba00ebf6c08%40%3Cdev.atlas.apache.org%3Ehttps://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rea63a4666ba245d2892471307772a2d8ce0f0741f341d6576625c1b3%40%3Cdev.atlas.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20201218-0006/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://groovy-lang.org/security.html#CVE-2020-17521https://lists.apache.org/thread.html/r4b2f13c302eec98838ff7475253091fb9b75bc1038016ba00ebf6c08%40%3Cdev.atlas.apache.org%3Ehttps://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rea63a4666ba245d2892471307772a2d8ce0f0741f341d6576625c1b3%40%3Cdev.atlas.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20201218-0006/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-12-07
Published