CVE-2020-17521Medium· 5.5▾ SunlitApache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.1%
1.1% → 1.1%
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
groovy >= 2.0.0, <= 2.4.20groovy >= 2.5.0, <= 2.5.13groovy >= 3.0.0, <= 3.0.6groovy = 4.0.0snapcenteragile_engineering_data_management = 6.2.1.0agile_plm_mcad_connector = 3.4agile_plm_mcad_connector = 3.6agile_product_lifecycle_management = 9.3.3agile_product_lifecycle_management = 9.3.6business_process_management_suite = 12.2.1.3.0business_process_management_suite = 12.2.1.4.0communications_brm_-_elastic_charging_engine = 11.3.0.9.0communications_brm_-_elastic_charging_engine = 12.0.0.3communications_diameter_signaling_router = 8.4.0.0communications_evolved_communications_application_server = 7.1communications_services_gatekeeper = 6.0communications_services_gatekeeper = 6.1communications_services_gatekeeper = 7.0healthcare_data_repository = 7.0.2hospitality_opera_5 = 5.6ilearning = 6.2ilearning = 6.3insurance_policy_administration >= 11.0, <= 11.3.1jd_edwards_enterpriseone_orchestrator = 9.2.6.0primavera_gateway >= 17.12.0, <= 17.12.10primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12retail_bulk_data_integration = 15.0.3.0retail_bulk_data_integration = 16.0.3.0retail_merchandising_system = 16.0.3retail_store_inventory_management = 14.1.3.10retail_store_inventory_management = 15.0.3.5retail_store_inventory_management = 16.0.3.5atlas = 2.1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71290Critical· 9.1Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient
CVE-2026-68569High· 8.1Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g
CVE-2026-87976High· 8.1Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests
CVE-2026-86089High· 7.1Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests
CVE-2026-81866Medium· 4.3Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration
CVE-2026-82561Medium· 6.5Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…