In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 05:06
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2020/12/06/1 - Mailing List, Third Party Advisory | |
| References | () https://blog.jetbrains.com/blog/2020/08/06/jetbrains-security-bulletin-q2-2020/ - Vendor Advisory | |
| References | () https://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cannounce.apache.org%3E - | |
| References | () https://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cdev.groovy.apache.org%3E - | |
| References | () https://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cusers.groovy.apache.org%3E - | |
| References | () https://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3E - | |
| References | () https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory | |
| References | () https://www.oracle.com/security-alerts/cpuoct2021.html - Patch, Third Party Advisory | 
07 Nov 2023, 03:17
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
    
        
        
  | 
Information
                Published : 2020-08-08 21:15
Updated : 2024-11-21 05:06
NVD link : CVE-2020-15824
Mitre link : CVE-2020-15824
CVE.ORG link : CVE-2020-15824
JSON object : View
Products Affected
                jetbrains
- kotlin
 
oracle
- communications_cloud_native_core_policy
 - banking_extensibility_workbench
 
CWE
                
                    
                        
                        CWE-269
                        
            Improper Privilege Management
