cbcvebase.
CVE-2020-11979
published 2020-10-01

CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access…

PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
8.24%
94.3th percentile
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
apacheant
apacheant>= 0 < 1.10.9-11.10.9-1
apacheant>= 0 < 1.10.9-11.10.9-1
apacheant>= 0 < 1.10.9-11.10.9-1
apacheant>= 0 < 1.10.9-11.10.9-1
debianant< ant 1.10.9-1 (bookworm)ant 1.10.9-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gradlegradle< 6.8.06.8.0
msrccm1_ant_1.10.11-1_on_cbl_mariner_1.0
oracleagile_engineering_data_management
oracleapi_gateway
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_treasury_management
oraclecommunications_unified_inventory_management
oraclecommunications_unified_inventory_management
oracledata_integrator
oracledata_integrator
oracleendeca_information_discovery_studio

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa6.3MEDIUM
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.