5.5

CVE-2020-17521

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheGroovy Version >= 2.0.0 <= 2.4.20
ApacheGroovy Version >= 2.5.0 <= 2.5.13
ApacheGroovy Version >= 3.0.0 <= 3.0.6
ApacheGroovy Version4.0.0 Updatealpha1
NetappSnapcenter Version-
OracleAgile Plm Version9.3.3
OracleAgile Plm Version9.3.6
OracleHospitality Opera 5 Version5.6
OracleIlearning Version6.2
OracleIlearning Version6.3
OracleInsurance Policy Administration Version >= 11.0 <= 11.3.1
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.10
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleRetail Bulk Data Integration Version15.0.3.0
OracleRetail Bulk Data Integration Version16.0.3.0
ApacheAtlas Version2.1.0 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.549
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N