CVE-2020-15824: JetBrains Kotlin
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
Affected products
- JetBrains Kotlin: version 1.4.0 only
- Oracle Banking Extensibility Workbench: version 14.2 only; version 14.3 only; version 14.5 only
- Oracle Communications Cloud Native Core Policy: version 1.14.0 only
Published 2020-08-08. Last modified 2026-06-17.