Insecure Temporary File in JUnit - CVE-2020-15250
Published: October 12, 2020 / Updated: January 7, 2021
JUnit
API Manager
Oracle Banking Liquidity Management
API Gateway
Oracle WebLogic Server
TensorFlow
Netcool/OMNIbus
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
IBM Sterling B2B Integrator
Tivoli Composite Application Manager for Transactions
IBM Disconnected Log Collector
JD Edwards EnterpriseOne Tools
Oracle Communications Cloud Native Core Policy
Apache Pulsar
Voice Gateway
junit (Alpine package)
junit4-doc (Ubuntu package)
junit4 (Ubuntu package)
junit
junit-help
Knowledge Catalog Premium Cartridge
IBM Business Automation Manager Open Editions
Business Automation Insights
IBM Security Risk Manager
Cloudera Observability with IBM
Engineering Test Management
MongoDB Enterprise Advanced with IBM
IBM Security Guardium
Ubuntu
openEuler
watsonx.data
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the application is using the test rule TemporaryFolder that stores sensitive information in temporary files in the system temporary directory, accessible by other system users. A local user can read temporary files and obtain sensitive information, related to the application.
How to mitigate CVE-2020-15250
Sources
- https://github.com/junit-team/junit4/blob/7852b90cfe1cea1e0cdaa19d490c83f0d8684b50/doc/ReleaseNotes4.13.1.md
- https://github.com/junit-team/junit4/commit/610155b8c22138329f0723eec22521627dbc52ae
- https://github.com/junit-team/junit4/issues/1676
- https://github.com/junit-team/junit4/security/advisories/GHSA-269g-pwp5-87pp
- https://junit.org/junit4/javadoc/4.13/org/junit/rules/TemporaryFolder.html
- https://lists.apache.org/thread.html/r500517c23200fb2fdb0b82770a62dd6c88b3521cfb01cfd0c76e3f8b@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5f8841507576f595bb783ccec6a7cb285ea90d4e6f5043eae0e61a41@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r717877028482c55acf604d7a0106af4ca05da4208c708fb157b53672@%3Ccommits.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r95f8ef60c4b3a5284b647bb3132cda08e6fadad888a66b84f49da0b0@%3Ccommits.creadur.apache.org%3E
- https://lists.apache.org/thread.html/ra1bdb9efae84794e8ffa2f8474be8290ba57830eefe9714b95da714b@%3Cdev.pdfbox.apache.org%3E
- https://lists.apache.org/thread.html/rb2771949c676ca984e58a5cd5ca79c2634dee1945e0406e48e0f8457@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rbaec90e699bc7c7bd9a053f76707a36fda48b6d558f31dc79147dbf9@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rc49cf1547ef6cac1be4b3c92339b2cae0acacf5acaba13cfa429a872@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rde385b8b53ed046600ef68dd6b4528dea7566aaddb02c3e702cc28bc@%3Ccommits.creadur.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/11/msg00003.html