cbcvebase.
CVE-2020-11979
published 2020-10-01

CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access…

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
apacheant
apacheant>= 0 < 1.10.9-11.10.9-1
apacheant>= 0 < 1.10.9-11.10.9-1
apacheant>= 0 < 1.10.9-11.10.9-1
apacheant>= 0 < 1.10.9-11.10.9-1
debianant< ant 1.10.9-1 (bookworm)ant 1.10.9-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gradlegradle< 6.8.06.8.0
msrccm1_ant_1.10.11-1_on_cbl_mariner_1.0
oracleagile_engineering_data_management
oracleapi_gateway
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_treasury_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracledata_integrator
oracledata_integrator
oracleendeca_information_discovery_studio

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
ghsa6.3MEDIUM
osv7.5HIGH