← Back

CVE-2020-11979

nvd nist
Published: Oct 1, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Affected (71)

Products: Apache: Ant · Gradle: Gradle · Fedoraproject: Fedora · +1 more
Show all products
1 product
Ant
1 product
Gradle
1 product
Fedora
34 products
Agile Engineering Data Management
Api Gateway
Banking Platform
Banking Treasury Management
Data Integrator
Enterprise Repository
Flexcube Private Banking
Primavera Gateway
Primavera Unifier
Real Time Decision Server
Retail Assortment Planning
Retail Eftlink
Retail Financial Integration
Retail Integration Bus
Retail Item Planning
Retail Macro Space Optimization
Retail Merchandising System
Retail Regular Price Optimization
Retail Replenishment Optimization
Retail Service Backbone
Retail Size Profile Optimization
Retail Store Inventory Management
Retail Xstore Point Of Service
Storagetek Acsls
Storagetek Tape Analytics
Timesten In Memory Database
Utilities Framework
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.10.8
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.8.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Version 33
Configuration D
66 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2.1.0
Version 11.1.2.4.0
Oracle
Version 2.4.0
Version 2.4.1
Version 2.6.2
Version 2.7.0
Version 2.7.1
Version 2.8.0
Version 14.4
Oracle
Version 7.4.0
Version 7.4.1
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 3.2.0.0
Version 11.1.1.7.0
Oracle
From 8.0.6 to 8.0.9
Version 8.1.0
Version 8.1.1
Oracle
Version 12.0.0
Version 12.1.0
Oracle
From 16.2.0 to 16.2.11
From 17.12.0 to 17.12.9
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 19.12
Version 20.12
Oracle
Version 11.1.1.9.0
Version 3.2.0.0
Version 14.1
Version 16.0.3
Version 16.0.3
Oracle
Version 19.0.1
Version 20.0.0
Oracle
Version 14.1.3
Version 15.0.3
Version 16.0.3
Version 15.0.3
Version 16.0.3
Version 16.0.3
Version 16.0.3
Oracle
Version 14.1.3.2
Version 16.0.3
Version 14.1
Version 16.0.3
Version 16.0.3
Oracle
Version 14.1.3
Version 15.0.3
Version 16.0.3
Version 16.0.3
Oracle
Version 14.1.3.9
Version 15.0.3.0
Version 16.0.3.0
Oracle
Version 15.0.4
Version 16.0.6
Version 17.0.4
Version 18.0.3
Version 19.0.2
Version 8.5.1
Version 2.4
Before 11.2.2.8.27
Oracle
Version 4.3.0.5.0
Version 4.3.0.6.0
Version 4.4.0.0.0
Version 4.4.0.2.0

References (38)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.