CVE-2020-11979
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Affected (71)
Show all products
Apache: Ant · Gradle: Gradle · Fedoraproject: Fedora · Oracle: Agile Engineering Data Management, Api Gateway, Banking Platform, Banking Treasury Management, Communications Unified Inventory Management, Data Integrator, Endeca Information Discovery Studio, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Flexcube Private Banking, Primavera Gateway, Primavera Unifier, Real Time Decision Server, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Category Management Planning & Optimization, Retail Eftlink, Retail Financial Integration, Retail Integration Bus, Retail Item Planning, Retail Macro Space Optimization, Retail Merchandise Financial Planning, Retail Merchandising System, Retail Predictive Application Server, Retail Regular Price Optimization, Retail Replenishment Optimization, Retail Service Backbone, Retail Size Profile Optimization, Retail Store Inventory Management, Retail Xstore Point Of Service, Storagetek Acsls, Storagetek Tape Analytics, Timesten In Memory Database, Utilities Framework
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 31 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.1.0 | |
| Version 11.1.2.4.0 | |
| Version 2.4.0 | |
| Version 14.4 | |
| Version 7.4.0 | |
| Version 12.2.1.3.0 | |
| Version 3.2.0.0 | |
| Version 11.1.1.7.0 | |
| From 8.0.6 to 8.0.9 | |
| Version 12.0.0 | |
| From 16.2.0 to 16.2.11 | |
| From 17.7 to 17.12 | |
| Version 11.1.1.9.0 | |
| Version 14.1 | |
| Version 16.0.3 | |
| Version 16.0.3 | |
| Version 19.0.1 | |
| Version 14.1.3 | |
| Version 15.0.3 | |
| Version 16.0.3 | |
| Version 16.0.3 | |
| Version 16.0.3 | |
| Version 14.1.3.2 | |
| Version 14.1 | |
| Version 16.0.3 | |
| Version 16.0.3 | |
| Version 14.1.3 | |
| Version 16.0.3 | |
| Version 14.1.3.9 | |
| Version 15.0.4 | |
| Version 8.5.1 | |
| Version 2.4 | |
| Before 11.2.2.8.27 | |
| Version 4.3.0.5.0 |
References (38)
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.