Insecure Temporary File in JUnit - CVE-2020-15250
Published: October 12, 2020 / Updated: January 7, 2021
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the application is using the test rule TemporaryFolder that stores sensitive information in temporary files in the system temporary directory, accessible by other system users. A local user can read temporary files and obtain sensitive information, related to the application.
Affected software
API Manager
Oracle Banking Liquidity Management
API Gateway
Oracle WebLogic Server
TensorFlow
Netcool/OMNIbus
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
IBM Sterling B2B Integrator
Tivoli Composite Application Manager for Transactions
IBM Disconnected Log Collector
JD Edwards EnterpriseOne Tools
Oracle Communications Cloud Native Core Policy
Apache Pulsar
Voice Gateway
junit (Alpine package)
junit4-doc (Ubuntu package)
junit4 (Ubuntu package)
junit
junit-help
Knowledge Catalog Premium Cartridge
IBM Business Automation Manager Open Editions
Business Automation Insights
IBM Security Risk Manager
Cloudera Observability with IBM
Engineering Test Management
MongoDB Enterprise Advanced with IBM
IBM Security Guardium
Ubuntu
openEuler
watsonx.data
How to mitigate CVE-2020-15250
API Manager - update to August 2022
API Gateway - update to August 2022
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
IBM Disconnected Log Collector - update to 1.8.7
Apache Pulsar - update to 2.8.0
Knowledge Catalog Premium Cartridge - update to 5.2
Netcool/OMNIbus - update to 8.1.0.37
IBM Business Automation Manager Open Editions - update to 9.2.1
JD Edwards EnterpriseOne Tools - update to 9.2.7.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Security Risk Manager - update to 1.8.0.0
IBM Cloud Pak for Security - update to 1.11.2.0
watsonx.data - update to 2.0.1
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Transformation Advisor - update to 3.6.2
junit4-doc (Ubuntu package) - addressed in versions 4.12-4ubuntu1.1, 4.12-8ubuntu0.20.04.1, 4.12-8ubuntu0.20.10.1, 4.12-8~18.04.1
junit4 (Ubuntu package) - addressed in versions 4.12-4ubuntu1.1, 4.12-8ubuntu0.20.04.1, 4.12-8ubuntu0.20.10.1, 4.12-8~18.04.1
junit - update to 4.12-13
junit-help - update to 4.12-13
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.6, 6.1.1.1, 6.1.2.0
Engineering Test Management - addressed in versions 7.0.1.0.22, 7.0.2.0.23
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
MongoDB Enterprise Advanced with IBM - update to 8.0.12
External References
- https://github.com/junit-team/junit4/blob/7852b90cfe1cea1e0cdaa19d490c83f0d8684b50/doc/ReleaseNotes4.13.1.md
- https://github.com/junit-team/junit4/commit/610155b8c22138329f0723eec22521627dbc52ae
- https://github.com/junit-team/junit4/issues/1676
- https://github.com/junit-team/junit4/security/advisories/GHSA-269g-pwp5-87pp
- https://junit.org/junit4/javadoc/4.13/org/junit/rules/TemporaryFolder.html
- https://lists.apache.org/thread.html/r500517c23200fb2fdb0b82770a62dd6c88b3521cfb01cfd0c76e3f8b@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5f8841507576f595bb783ccec6a7cb285ea90d4e6f5043eae0e61a41@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r717877028482c55acf604d7a0106af4ca05da4208c708fb157b53672@%3Ccommits.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r95f8ef60c4b3a5284b647bb3132cda08e6fadad888a66b84f49da0b0@%3Ccommits.creadur.apache.org%3E
- https://lists.apache.org/thread.html/ra1bdb9efae84794e8ffa2f8474be8290ba57830eefe9714b95da714b@%3Cdev.pdfbox.apache.org%3E
- https://lists.apache.org/thread.html/rb2771949c676ca984e58a5cd5ca79c2634dee1945e0406e48e0f8457@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rbaec90e699bc7c7bd9a053f76707a36fda48b6d558f31dc79147dbf9@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rc49cf1547ef6cac1be4b3c92339b2cae0acacf5acaba13cfa429a872@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rde385b8b53ed046600ef68dd6b4528dea7566aaddb02c3e702cc28bc@%3Ccommits.creadur.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/11/msg00003.html
Related Security Bulletins
- Information disclosure in JUnit
- Multiple vulnerabilities in TensorFlow
- Insecure Temporary File in junit (Alpine package)
- Multiple vulnerabilities in Apache Pulsar
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Ubuntu update for junit4
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Security Risk Manager on CP4S
- Information disclosure in IBM Sterling B2B Integrator
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Insecure temporary file in IBM Engineering Test Management (ETM)
- Insecure temporary file in ITCAM for Transactions
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- openEuler 20.03 LTS SP1 update for junit
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Oracle WebLogic Server
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge
- IBM Netcool/OMNIbus update for JUnit4