Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Groovy 安全漏洞
Vulnerability Description
Apache Groovy是美国阿帕奇(Apache)基金会的一款基于Java平台的面向对象编程语言。 Apache Groovy provides 存在安全漏洞,该漏洞源于Apache Groovy提供了扩展方法来帮助创建临时目录。在此修复之前,Groovy对这些扩展方法的实现使用的是一个已被取代的Java JDK方法调用,在某些上下文中,这种方法在某些操作系统上可能不安全。未使用本建议中提到的扩展方法的用户不受影响,以下产品及版本受到影响:2.0版本至2.4.20版本, 2.5.0版本至2.5.13版
CVSS Information
N/A
Vulnerability Type
N/A