CVE-2020-1945
published 2020-05-14CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and…
PriorityP434medium6.3CVSS 3.1
AVLACHPRLUINSUCHIHAN
EPSS
1.81%
76.2th percentile
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Affected
173 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ant | — | — |
| apache | ant | >= 0 < 1.10.9-1 | 1.10.9-1 |
| apache | ant | >= 0 < 1.10.8-1 | 1.10.8-1 |
| apache | ant | >= 0 < 1.10.9-1 | 1.10.9-1 |
| apache | ant | >= 0 < 1.10.8-1 | 1.10.8-1 |
| apache | ant | >= 0 < 1.10.9-1 | 1.10.9-1 |
| apache | ant | >= 0 < 1.10.8-1 | 1.10.8-1 |
| apache | ant | >= 0 < 1.10.9-1 | 1.10.9-1 |
| apache | ant | >= 0 < 1.10.8-1 | 1.10.8-1 |
| apache | ant | 1.1 – 1.9.14 | — |
| apache | ant | 1.10.0 – 1.10.7 | — |
| canonical | ubuntu_linux | — | — |
| debian | ant | < ant 1.10.9-1 (bookworm) | ant 1.10.9-1 (bookworm) |
| debian | ant | < ant 1.10.8-1 (bookworm) | ant 1.10.8-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gradle | gradle | < 6.8.0 | 6.8.0 |
| msrc | cm1_ant_1.10.11-1_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | api_gateway | — | — |
| oracle | banking_enterprise_collections | 2.7.0 – 2.9.0 | — |
| oracle | banking_liquidity_management | 14.0.0 – 14.4.0 | — |
| oracle | banking_platform | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
ghsa8.8HIGH
osv8.8HIGH
vendor_oracle9.1MEDIUM
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Retail Extract Transform and Load 13.2.5/13.2.8 Mathematical Operators information disclosure (Nessus ID 316177)
vuldb·2026-05-24·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Retail Extract Transform and Load 13.2.5/13.2.8 Mathematical Operators information disclosure (Nessus ID 316177)
A vulnerability, which was classified as very critical, has been found in Oracle Retail Extract Transform and Load 13.2.5/13.2.8. This affects an unknown function of the component Mathematical Operators. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2020-1945. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
VulDB
Oracle Banking Liquidity Management up to 14.4.0 Common information disclosure (Nessus ID 316177)
vuldb·2026-05-24·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Banking Liquidity Management up to 14.4.0 Common information disclosure (Nessus ID 316177)
A vulnerability described as very critical has been identified in Oracle Banking Liquidity Management up to 14.4.0. This affects an unknown part of the component Common. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2020-1945. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Real-Time Decision Server 3.2.1.0 Decision Studio information disclosure (Nessus ID 316177)
vuldb·2026-05-24·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Real-Time Decision Server 3.2.1.0 Decision Studio information disclosure (Nessus ID 316177)
A vulnerability labeled as very critical has been found in Oracle Real-Time Decision Server 3.2.1.0. Affected by this issue is some unknown functionality of the component Decision Studio. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2020-1945. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
VulDB
Oracle Health Sciences Information Manager 3.0.0/3.0.1/3.0.2 Health Record Locator information disclosure (Nessus ID 316177)
vuldb·2026-05-24·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Health Sciences Information Manager 3.0.0/3.0.1/3.0.2 Health Record Locator information disclosure (Nessus ID 316177)
A vulnerability was found in Oracle Health Sciences Information Manager 3.0.0/3.0.1/3.0.2 and classified as very critical. This impacts an unknown function of the component Health Record Locator. Such manipulation leads to information disclosure.
This vulnerability is traded as CVE-2020-1945. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
VulDB
Oracle Data Integrator 12.2.1.3.0/12.2.1.4.0 Apache Ant exposure of resource (Nessus ID 316177)
vuldb·2026-05-24·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Data Integrator 12.2.1.3.0/12.2.1.4.0 Apache Ant exposure of resource (Nessus ID 316177)
A vulnerability classified as critical was found in Oracle Data Integrator 12.2.1.3.0/12.2.1.4.0. This vulnerability affects unknown code of the component Apache Ant. Executing a manipulation can lead to exposure of resource.
This vulnerability is handled as CVE-2020-1945. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
VulDB
Oracle Retail Returns Management 14.0/14.1 Apache Ant exposure of resource (Nessus ID 316177)
vuldb·2026-05-24·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Retail Returns Management 14.0/14.1 Apache Ant exposure of resource (Nessus ID 316177)
A vulnerability classified as critical has been found in Oracle Retail Returns Management 14.0/14.1. Affected by this vulnerability is an unknown functionality of the component Apache Ant. The manipulation leads to exposure of resource.
This vulnerability is traded as CVE-2020-1945. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
OSV
TemporaryFolder on unix-like systems does not limit access to created files
osv·2022-11-23
CVE-2022-41946 [MEDIUM] TemporaryFolder on unix-like systems does not limit access to created files
TemporaryFolder on unix-like systems does not limit access to created files
**Vulnerability**
`PreparedStatement.setText(int, InputStream)`
and
`PreparedStatemet.setBytea(int, InputStream)`
will create a temporary file if the InputStream is larger than 51k
Example of vulnerable code:
```java
String s = "some very large string greater than 51200 bytes";
PreparedStatement.setInputStream(1, new ByteArrayInputStream(s.getBytes()) );
```
This will create a temporary file which is readable by other users on Unix like systems, but not MacOS.
Impact
On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system.
GHSA
TemporaryFolder on unix-like systems does not limit access to created files
ghsa·2022-11-23
CVE-2022-41946 [MEDIUM] CWE-200 TemporaryFolder on unix-like systems does not limit access to created files
TemporaryFolder on unix-like systems does not limit access to created files
**Vulnerability**
`PreparedStatement.setText(int, InputStream)`
and
`PreparedStatemet.setBytea(int, InputStream)`
will create a temporary file if the InputStream is larger than 51k
Example of vulnerable code:
```java
String s = "some very large string greater than 51200 bytes";
PreparedStatement.setInputStream(1, new ByteArrayInputStream(s.getBytes()) );
```
This will create a temporary file which is readable by other users on Unix like systems, but not MacOS.
Impact
On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system.
OSV
Local information disclosure via system temporary directory
osv·2021-04-23·CVSS 8.8
CVE-2021-28168 [HIGH] Local information disclosure via system temporary directory
Local information disclosure via system temporary directory
## Impact
Eclipse Jersey 2.28 - 2.33 and Eclipse Jersey 3.0.0 - 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the `File.createTempFile` which creates a file inside of the system temporary directory with the permissions: `-rw-r--r--`. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.
## Workaround
This issue can be mitigated by manually setting the `java.io.tmpdir` system property when launching the JVM.
## Patches
Jersey 2.34 and 3.0.2 forward sets the correct permissions on the temporary file created by Jersey.
### References
- https://github.com/ecli
GHSA
Local information disclosure via system temporary directory
ghsa·2021-04-23·CVSS 8.8
CVE-2021-28168 [HIGH] CWE-378 Local information disclosure via system temporary directory
Local information disclosure via system temporary directory
## Impact
Eclipse Jersey 2.28 - 2.33 and Eclipse Jersey 3.0.0 - 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the `File.createTempFile` which creates a file inside of the system temporary directory with the permissions: `-rw-r--r--`. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.
## Workaround
This issue can be mitigated by manually setting the `java.io.tmpdir` system property when launching the JVM.
## Patches
Jersey 2.34 and 3.0.2 forward sets the correct permissions on the temporary file created by Jersey.
### References
- https://github.com/ecli
GHSA
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
ghsa·2021-02-08
CVE-2021-21290 [MEDIUM] CWE-378 Local Information Disclosure Vulnerability in Netty on Unix-Like systems
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
### Impact
When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled.
The CVSSv3.1 score of this vulnerability is calculated to be a [6.2/10](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&version=3.1)
### Vulnerability Details
On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems.
The method `File.createTempFile` on unix-like systems
OSV
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
osv·2021-02-08
CVE-2021-21290 [MEDIUM] Local Information Disclosure Vulnerability in Netty on Unix-Like systems
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
### Impact
When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled.
The CVSSv3.1 score of this vulnerability is calculated to be a [6.2/10](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N&version=3.1)
### Vulnerability Details
On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems.
The method `File.createTempFile` on unix-like systems
GHSA
Code injection in Apache Ant
ghsa·2021-02-03·CVSS 6.3
CVE-2020-11979 [MEDIUM] CWE-74 Code injection in Apache Ant
Code injection in Apache Ant
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
OSV
Code injection in Apache Ant
osv·2021-02-03·CVSS 6.3
CVE-2020-11979 [MEDIUM] Code injection in Apache Ant
Code injection in Apache Ant
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
OSV
Local Temp Directory Hijacking Vulnerability
osv·2020-11-04
CVE-2020-27216 [HIGH] Local Temp Directory Hijacking Vulnerability
Local Temp Directory Hijacking Vulnerability
### Impact
On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.
Additionally, any user code uses of [WebAppContext::getTempDirectory](https://www.eclipse.org/jetty/javadoc/9.4.31.v20200723/org/eclipse/jetty/webapp/WebAppCon
GHSA
Local Temp Directory Hijacking Vulnerability
ghsa·2020-11-04
CVE-2020-27216 [HIGH] CWE-378 Local Temp Directory Hijacking Vulnerability
Local Temp Directory Hijacking Vulnerability
### Impact
On Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory. If the attacker wins the race then they will have read and write permission to the subdirectory used to unpack web applications, including their WEB-INF/lib jar files and JSP files. If any code is ever executed out of this temporary directory, this can lead to a local privilege escalation vulnerability.
Additionally, any user code uses of [WebAppContext::getTempDirectory](https://www.eclipse.org/jetty/javadoc/9.4.31.v20200723/org/eclipse/jetty/webapp/WebAppCon
OSV
TemporaryFolder on unix-like systems does not limit access to created files
osv·2020-10-12
CVE-2020-15250 [MEDIUM] TemporaryFolder on unix-like systems does not limit access to created files
TemporaryFolder on unix-like systems does not limit access to created files
### Vulnerability
The JUnit4 test rule [TemporaryFolder](https://junit.org/junit4/javadoc/4.13/org/junit/rules/TemporaryFolder.html) contains a local information disclosure vulnerability.
Example of vulnerable code:
```java
public static class HasTempFolder {
@Rule
public TemporaryFolder folder = new TemporaryFolder();
@Test
public void testUsingTempFolder() throws IOException {
folder.getRoot(); // Previous file permissions: `drwxr-xr-x`; After fix:`drwx------`
File createdFile= folder.newFile("myfile.txt"); // unchanged/irrelevant file permissions
File createdFolder= folder.newFolder("subfolder"); // unchanged/irrelevant file permissions
// ...
}
}
```
### Impact
On Unix like systems, the system's temporary
GHSA
TemporaryFolder on unix-like systems does not limit access to created files
ghsa·2020-10-12
CVE-2020-15250 [MEDIUM] CWE-200 TemporaryFolder on unix-like systems does not limit access to created files
TemporaryFolder on unix-like systems does not limit access to created files
### Vulnerability
The JUnit4 test rule [TemporaryFolder](https://junit.org/junit4/javadoc/4.13/org/junit/rules/TemporaryFolder.html) contains a local information disclosure vulnerability.
Example of vulnerable code:
```java
public static class HasTempFolder {
@Rule
public TemporaryFolder folder = new TemporaryFolder();
@Test
public void testUsingTempFolder() throws IOException {
folder.getRoot(); // Previous file permissions: `drwxr-xr-x`; After fix:`drwx------`
File createdFile= folder.newFile("myfile.txt"); // unchanged/irrelevant file permissions
File createdFolder= folder.newFolder("subfolder"); // unchanged/irrelevant file permissions
// ...
}
}
```
### Impact
On Unix like systems, the system's temporary
OSV
CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1
osv·2020-10-01·CVSS 7.5
CVE-2020-11979 [HIGH] CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
OSV
Sensitive Data Exposure in Apache Ant
osv·2020-09-14
CVE-2020-1945 [MEDIUM] Sensitive Data Exposure in Apache Ant
Sensitive Data Exposure in Apache Ant
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
GHSA
Sensitive Data Exposure in Apache Ant
ghsa·2020-09-14
CVE-2020-1945 [MEDIUM] CWE-200 Sensitive Data Exposure in Apache Ant
Sensitive Data Exposure in Apache Ant
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
OSV
CVE-2020-1945: Apache Ant 1
osv·2020-05-14·CVSS 6.3
CVE-2020-1945 [MEDIUM] CVE-2020-1945: Apache Ant 1
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Ant) — CVE-2020-1945
vendor_oracle·2024-07-15·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Ant) — CVE-2020-1945
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 6.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Return Tickets (Apache Ant) — CVE-2020-1945
vendor_oracle·2021-10-15·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Return Tickets (Apache Ant) — CVE-2020-1945
Oracle Oracle Retail Applications Risk Matrix: Return Tickets (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 6.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Install, config, upgrade (Apache Ant) — CVE-2020-1945
vendor_oracle·2021-07-15·CVSS 6.3
CVE-2020-1945 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Install, config, upgrade (Apache Ant) — CVE-2020-1945
Oracle Oracle Fusion Middleware Risk Matrix: Install, config, upgrade (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 6.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Health Sciences Applications Risk Matrix: Health Record Locator (Apache Ant) — CVE-2020-1945
vendor_oracle·2021-04-15·CVSS 9.1
CVE-2020-1945 [MEDIUM] Oracle Oracle Health Sciences Applications Risk Matrix: Health Record Locator (Apache Ant) — CVE-2020-1945
Oracle Oracle Health Sciences Applications Risk Matrix: Health Record Locator (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
Apache Ant vulnerability
vendor_ubuntu·2021-03-15
CVE-2020-1945 Apache Ant vulnerability
Title: Apache Ant vulnerability
Summary: Apache Ant would allow unintended access to files or execute arbitrary code.
It was discovered that Apache Ant created temporary files with insecure
permissions. An attacker could use this vulnerability to read sensitive
information leaked into /tmp, or potentially inject malicious code into a
project that is built with Apache Ant.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Ant) — CVE-2020-1945
vendor_oracle·2021-01-15·CVSS 6.2
CVE-2020-1945 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Ant) — CVE-2020-1945
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 6.2
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Apache Ant) — CVE-2020-1945
vendor_oracle·2020-10-15·CVSS 6.7
CVE-2020-1945 [MEDIUM] Oracle Oracle Communications Risk Matrix: IDIH (Apache Ant) — CVE-2020-1945
Oracle Oracle Communications Risk Matrix: IDIH (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 6.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2020 (OCT 2020)
Microsoft
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted
vendor_msrc·2020-10-13·CVSS 7.5
CVE-2020-11979 [HIGH] CWE-379 As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to t
Red Hat
ant: insecure temporary file
vendor_redhat·2020-10-01·CVSS 7.5
CVE-2020-11979 [HIGH] CWE-377 ant: insecure temporary file
ant: insecure temporary file
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Statement: ant as shipped in Red Hat Enterprise Linux 8 is not affected by this flaw because this flaw is caused by the patch for CVE-2020-1945, however, it was never applied to ant as shipped in Red Hat Enterprise Linux 8, because the decision was made by Engineering to WONTFIX that flaw.
In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that compris
Oracle
Oracle Oracle Communications Applications Risk Matrix: Online Help (Apache Ant) — CVE-2020-1945
vendor_oracle·2020-07-15·CVSS 9.1
CVE-2020-1945 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Online Help (Apache Ant) — CVE-2020-1945
Oracle Oracle Communications Applications Risk Matrix: Online Help (Apache Ant) vulnerability
CVE: CVE-2020-1945
CVSS: 9.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Ubuntu
Apache Ant vulnerability
vendor_ubuntu·2020-06-01
CVE-2020-1945 Apache Ant vulnerability
Title: Apache Ant vulnerability
Summary: Apache Ant could leak sensitive information or be made to run programs
as your login.
It was discovered that Apache Ant created temporary files with insecure
permissions. An attacker could use this vulnerability to read sensitive
information leaked into /tmp, or potentially inject malicious code into a
project that is built with Apache Ant.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ant: insecure temporary file vulnerability
vendor_redhat·2020-05-13·CVSS 6.3
CVE-2020-1945 [MEDIUM] CWE-377 ant: insecure temporary file vulnerability
ant: insecure temporary file vulnerability
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Statement: In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of ant package.
Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix.
This may be fixed in the future.
[1] https://docs.openshift.com/container-platfor
Debian
CVE-2020-11979: ant - As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of tem...
vendor_debian·2020·CVSS 7.5
CVE-2020-11979 [HIGH] CVE-2020-11979: ant - As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of tem...
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Scope: local
bookworm: resolved (fixed in 1.10.9-1)
bullseye: resolved (fixed in 1.10.9-1)
forky: resolved (fixed in 1.10.9-1)
sid: resolved (fixed in 1.10.9-1)
trixie: resolved (fixed in 1.10.9-1)
Debian
CVE-2020-1945: ant - Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directo...
vendor_debian·2020·CVSS 6.3
CVE-2020-1945 [MEDIUM] CVE-2020-1945: ant - Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directo...
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Scope: local
bookworm: resolved (fixed in 1.10.8-1)
bullseye: resolved (fixed in 1.10.8-1)
forky: resolved (fixed in 1.10.8-1)
sid: resolved (fixed in 1.10.8-1)
trixie: resolved (fixed in 1.10.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1945 ant:1.10/ant: insecure temporary file vulnerability [fedora-all]
bugzilla·2020-05-19·CVSS 6.3
CVE-2020-1945 [MEDIUM] CVE-2020-1945 ant:1.10/ant: insecure temporary file vulnerability [fedora-all]
CVE-2020-1945 ant:1.10/ant: insecure temporary file vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2020-1945 ant: insecure temporary file vulnerability
bugzilla·2020-05-19·CVSS 6.3
CVE-2020-1945 [MEDIUM] CVE-2020-1945 ant: insecure temporary file vulnerability
CVE-2020-1945 ant: insecure temporary file vulnerability
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
References:
https://issues.apache.org/jira/browse/RAT-269?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanel
https://lists.apache.org/thread.html/r8e592bbfc016a5dbe2a8c0e81ff99682b9c78c453621b82c14e7b75e%40%3Cdev.ant.apache.org%3E
Discussion:
Created ant tracking bugs for this issue:
Affects: fedora-all [bug 1837445]
Created ant:1.10/ant
Bugzilla
CVE-2020-1945 ant: insecure temporary file vulnerability [fedora-all]
bugzilla·2020-05-19·CVSS 6.3
CVE-2020-1945 [MEDIUM] CVE-2020-1945 ant: insecure temporary file vulnerability [fedora-all]
CVE-2020-1945 ant: insecure temporary file vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2020/09/30/6http://www.openwall.com/lists/oss-security/2020/12/06/1https://lists.apache.org/thread.html/r0d08a96ba9de8aa435f32944e8b2867c368a518d4ff57782e3637335%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1863b9ce4c3e4b1e5b0c671ad05545ba3eb8399616aa746af5dfe1b1%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1a9c992d7c8219dc15b4ad448649f0ffdaa88d76ef6a0035c49455f5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1b32c76afffcf676e13ed635a3332f3e46e6aaa7722eb3fc7a28f58e%40%3Cdev.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2704fb14ce068c64759a986f81d5b5e42ab434fa13d0f444ad52816b%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r3cea0f3da4f6d06d7afb6c0804da8e01773a0f50a09b8d9beb2cda65%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r4b2904d64affd4266cd72ccb2fc3927c1c2f22009f183095aa46bf90%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r5dfc77048b1f9db26622dce91a6edf083d499397256594952fad5f35%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r6030d34ceacd0098538425c5dac8251ffc7fd90b886942bc7ef87858%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/r6970d196cd73863dafdbc3a7052562deedd338e3bd7d73d8171d92d6%40%3Ccommits.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/r6e295d792032ec02b32be3846c21a58857fba4a077d22c5842d69ba2%40%3Ctorque-dev.db.apache.org%3Ehttps://lists.apache.org/thread.html/r6edd3e2cb79ee635630d891b54a4f1a9cd8c7f639d6ee34e75fbe830%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r815f88d1044760176f30a4913b4baacd06f3eae4eb662de7388e46d8%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r8e24abb7dd77cda14c6df90a377c94f0a413bbfcec90a29540ff8adf%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r8e592bbfc016a5dbe2a8c0e81ff99682b9c78c453621b82c14e7b75e%40%3Cdev.ant.apache.org%3Ehttps://lists.apache.org/thread.html/r95dc943e47a211d29df605e14f86c280fc9fa8d828b2b53bd07673c9%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cdev.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cusers.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rb860063819b9c0990e1fbce29d83f4554766fe5a05e3b3939736bf2b%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/rb8ec556f176c83547b959150e2108e2ddf1d61224295941908b0a81f%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3Ehttps://lists.apache.org/thread.html/rc89e491b5b270fb40f1210b70554527b737c217ad2e831b643ead6bc%40%3Cuser.ant.apache.org%3Ehttps://lists.apache.org/thread.html/rce099751721c26a8166d8b6578293820832831a0b2cb8d93b8efa081%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rd7dda48ff835f4d0293949837d55541bfde3683bd35bd8431e324538%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rda80ac59119558eaec452e58ddfac2ccc9211da1c65f7927682c78b1%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rdaa9c51d5dc6560c9d2b3f3d742c768ad0705e154041e574a0fae45c%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/re1ce84518d773a94a613d988771daf9252c9cf7375a9a477009f9735%40%3Ccommits.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rf07feaf78afc8f701e21948a06ef92565d3dff1242d710f4fbf900b2%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rfd346609527a79662c48b1da3ac500ec30f29f7ddaa3575051e81890%40%3Ccommits.creadur.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EQBR65TINSJRN7PTPIVNYS33P535WM74/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRVAWTCVXJMRYKQKEXYSNBF7NLSR6OEI/https://security.gentoo.org/glsa/202007-34https://usn.ubuntu.com/4380-1/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00053.htmlhttp://www.openwall.com/lists/oss-security/2020/09/30/6http://www.openwall.com/lists/oss-security/2020/12/06/1https://lists.apache.org/thread.html/r0d08a96ba9de8aa435f32944e8b2867c368a518d4ff57782e3637335%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1863b9ce4c3e4b1e5b0c671ad05545ba3eb8399616aa746af5dfe1b1%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1a9c992d7c8219dc15b4ad448649f0ffdaa88d76ef6a0035c49455f5%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r1b32c76afffcf676e13ed635a3332f3e46e6aaa7722eb3fc7a28f58e%40%3Cdev.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r2704fb14ce068c64759a986f81d5b5e42ab434fa13d0f444ad52816b%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r3cea0f3da4f6d06d7afb6c0804da8e01773a0f50a09b8d9beb2cda65%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r4b2904d64affd4266cd72ccb2fc3927c1c2f22009f183095aa46bf90%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r5dfc77048b1f9db26622dce91a6edf083d499397256594952fad5f35%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/r6030d34ceacd0098538425c5dac8251ffc7fd90b886942bc7ef87858%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/r6970d196cd73863dafdbc3a7052562deedd338e3bd7d73d8171d92d6%40%3Ccommits.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/r6e295d792032ec02b32be3846c21a58857fba4a077d22c5842d69ba2%40%3Ctorque-dev.db.apache.org%3Ehttps://lists.apache.org/thread.html/r6edd3e2cb79ee635630d891b54a4f1a9cd8c7f639d6ee34e75fbe830%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r815f88d1044760176f30a4913b4baacd06f3eae4eb662de7388e46d8%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r8e24abb7dd77cda14c6df90a377c94f0a413bbfcec90a29540ff8adf%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r8e592bbfc016a5dbe2a8c0e81ff99682b9c78c453621b82c14e7b75e%40%3Cdev.ant.apache.org%3Ehttps://lists.apache.org/thread.html/r95dc943e47a211d29df605e14f86c280fc9fa8d828b2b53bd07673c9%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cdev.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/ra12c3e23b021f259a201648005b9946acd7f618a6f32301c97047967%40%3Cusers.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/ra9dab34bf8625511f23692ad0fcee2725f782e9aad6c5cdff6cf4465%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rb860063819b9c0990e1fbce29d83f4554766fe5a05e3b3939736bf2b%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/rb8ec556f176c83547b959150e2108e2ddf1d61224295941908b0a81f%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3Ehttps://lists.apache.org/thread.html/rc89e491b5b270fb40f1210b70554527b737c217ad2e831b643ead6bc%40%3Cuser.ant.apache.org%3Ehttps://lists.apache.org/thread.html/rce099751721c26a8166d8b6578293820832831a0b2cb8d93b8efa081%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rd7dda48ff835f4d0293949837d55541bfde3683bd35bd8431e324538%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rda80ac59119558eaec452e58ddfac2ccc9211da1c65f7927682c78b1%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rdaa9c51d5dc6560c9d2b3f3d742c768ad0705e154041e574a0fae45c%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/re1ce84518d773a94a613d988771daf9252c9cf7375a9a477009f9735%40%3Ccommits.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rf07feaf78afc8f701e21948a06ef92565d3dff1242d710f4fbf900b2%40%3Cdev.creadur.apache.org%3Ehttps://lists.apache.org/thread.html/rfd346609527a79662c48b1da3ac500ec30f29f7ddaa3575051e81890%40%3Ccommits.creadur.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EQBR65TINSJRN7PTPIVNYS33P535WM74/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRVAWTCVXJMRYKQKEXYSNBF7NLSR6OEI/https://security.gentoo.org/glsa/202007-34https://usn.ubuntu.com/4380-1/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.html
+ 4 more references
2020-05-14
Published