CVE-2020-1945
6.3
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.0 / Impact: 5.2
Source: NVD
Description
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Affected (117)
Show all products
Apache: Ant · Canonical: Ubuntu Linux · Fedoraproject: Fedora · Opensuse: Leap · Oracle: Agile Engineering Data Management, Banking Enterprise Collections, Banking Liquidity Management, Banking Platform, Business Process Management Suite, Category Management Planning & Optimization, Communications Asap, Communications Diameter Signaling Router, Communications Metasolv Solution, Communications Order And Service Management, Data Integrator, Endeca Information Discovery Studio, Enterprise Manager Ops Center, Enterprise Repository, Financial Services Analytical Applications Infrastructure, Flexcube Investor Servicing, Flexcube Private Banking, Health Sciences Information Manager, Primavera Gateway, Primavera Unifier, Rapid Planning, Real Time Decision Server, Retail Advanced Inventory Planning, Retail Assortment Planning, Retail Back Office, Retail Bulk Data Integration, Retail Central Office, Retail Data Extractor For Merchandising, Retail Extract Transform And Load, Retail Financial Integration, Retail Integration Bus, Retail Item Planning, Retail Macro Space Optimization, Retail Merchandise Financial Planning, Retail Merchandising System, Retail Point Of Service, Retail Predictive Application Server, Retail Regular Price Optimization, Retail Replenishment Optimization, Retail Returns Management, Retail Service Backbone, Retail Size Profile Optimization, Retail Store Inventory Management, Retail Xstore Point Of Service, Timesten In Memory Database, Utilities Framework
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 19.10 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 31 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.2.1.0 | |
| From 2.7.0 to 2.9.0 | |
| From 14.0.0 to 14.4.0 | |
| From 2.4.0 to 2.9.0 | |
| Version 12.2.1.3.0 | |
| Version 15.0.3 | |
| Version 7.3 | |
| From 8.0.0 to 8.2.2 | |
| Version 6.3.0 | |
| Version 7.3 | |
| Version 12.2.1.3.0 | |
| Version 3.2.0 | |
| Version 12.4.0.0 | |
| Version 11.1.1.7.0 | |
| From 8.0.6 to 8.1.0 | |
| Version 12.1.0 | |
| Version 12.0.0 | |
| From 3.0 to 3.0.2 | |
| From 16.2.0 to 16.2.11 | |
| From 17.7 to 17.12 | |
| Version 12.1 | |
| Version 3.2.1.0 | |
| Version 14.1 | |
| Version 15.0.3 | |
| Version 14.0 | |
| Version 15.0 | |
| Version 14.0 | |
| Version 1.10 | |
| Version 13.2.5 | |
| Version 14.1.3.2 | |
| Version 14.1.3.2 | |
| Version 15.0.3 | |
| Version 15.0.3 | |
| Version 15.0.3 | |
| Version 19.0.1 | |
| Version 14.0 | |
| Version 14.0.3 | |
| Version 15.0.3 | |
| Version 15.0.3 | |
| Version 14.0 | |
| Version 14.1.3.2 | |
| Version 15.0.3 | |
| Version 14.0.4 | |
| Version 15.0.4 | |
| Before 11.2.2.8.27 | |
| From 4.3.0.1.0 to 4.3.0.6.0 |
References (104)
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.