boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2020-15250

junit-team junit4 — Information disclosure in JUnit4
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  N  N    5.5   .0169   76.4     —
AFFECTED
  Product  Versions    Fixed
  junit4   < 4.13.1 –  —
TIMELINE
  Jun 25  Reserved by GitHub_M
  Oct 12  Published (CNA: GitHub_M)
  Oct 7   EXPLOIT PUBLISHED — CVE-2020-15250 (junit-team junit4). Public exploit reference added.
  Oct 7   RESCORED — CVE-2020-15250 (junit-team junit4). CVSS 4.4 → 5.5 (NVD).
CWE-732, CWE-200 · CNA: GitHub_M · CVSS v3.1 · 39 references · NVD status: Modified

Description

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not allow other users to overwrite the contents of these directories or files. This is purely an information disclosure vulnerability. This vulnerability impacts you if the JUnit tests write sensitive information, like API keys or passwords, into the temporary folder, and the JUnit tests execute in an environment where the OS has other untrusted users. Because certain JDK file system APIs were only added in JDK 1.7, this this fix is dependent upon the version of the JDK you are using. For Java 1.7 and higher users: this vulnerability is fixed in 4.13.1. For Java 1.6 and lower users: no patch is available, you must use the workaround below. If you are unable to patch, or are stuck running on Java 1.6, specifying the `java.io.tmpdir` system environment variable to a directory that is exclusively owned by the executing user will fix this vulnerability. For more information, including an example of vulnerable code, see the referenced GitHub Security Advisory.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
June 25, 2020ReservedReserved by GitHub_M
October 12, 2020PublishedPublished (CNA: GitHub_M)
October 7, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2020-15250 (junit-team junit4). Public exploit reference added.
October 7, 2026RESCOREDRESCORED — CVE-2020-15250 (junit-team junit4). CVSS 4.4 → 5.5 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
junit-teamjunit4—< 4.13.1—

Weaknesses

CWE-732 · CWE-200

References (39)

Related

Authoritative record: CVE-2020-15250 at cve.org

Vendors: junit-team

Weaknesses: CWE-732 · CWE-200

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2020-15250 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.