HIGH · 8.8

CVE-2020-15824

In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cach...

Vulnerability Description

In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
JetbrainsKotlin1.4.0
OracleBanking Extensibility Workbench14.2
OracleCommunications Cloud Native Core Policy1.14.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15824?

CVE-2020-15824 is a vulnerability with a CVSS score of 8.8 (HIGH). In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cach...

How severe is CVE-2020-15824?

CVE-2020-15824 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-15824?

Check the references section above for vendor advisories and patch information. Affected products include: Jetbrains Kotlin, Oracle Banking Extensibility Workbench, Oracle Communications Cloud Native Core Policy.