← Back

CVE-2020-1945

nvd nist
Published: May 14, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.0 / Impact: 5.2
Source: NVD

Description

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

Affected (117)

Products: Apache: Ant · Canonical: Ubuntu Linux · Fedoraproject: Fedora · +2 more
Show all products
1 product
Ant
1 product
Ubuntu Linux
1 product
Fedora
1 product
Leap
46 products
Agile Engineering Data Management
Banking Enterprise Collections
Banking Liquidity Management
Banking Platform
Business Process Management Suite
Communications Asap
Communications Metasolv Solution
Data Integrator
Enterprise Manager Ops Center
Enterprise Repository
Flexcube Investor Servicing
Flexcube Private Banking
Primavera Gateway
Primavera Unifier
Rapid Planning
Real Time Decision Server
Retail Assortment Planning
Retail Back Office
Retail Bulk Data Integration
Retail Central Office
Retail Extract Transform And Load
Retail Financial Integration
Retail Integration Bus
Retail Item Planning
Retail Macro Space Optimization
Retail Merchandising System
Retail Point Of Service
Retail Regular Price Optimization
Retail Replenishment Optimization
Retail Returns Management
Retail Service Backbone
Retail Size Profile Optimization
Retail Store Inventory Management
Retail Xstore Point Of Service
Timesten In Memory Database
Utilities Framework
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.1 to 1.9.14
From 1.10.0 to 1.10.7
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 19.10
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.2
Configuration E
111 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.2.1.0
From 2.7.0 to 2.9.0
From 14.0.0 to 14.4.0
From 2.4.0 to 2.9.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 15.0.3
Version 7.3
From 8.0.0 to 8.2.2
Version 6.3.0
Oracle
Version 7.3
Version 7.4
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 3.2.0
Version 12.4.0.0
Version 11.1.1.7.0
From 8.0.6 to 8.1.0
Oracle
Version 12.1.0
Version 12.3.0
Version 12.4.0
Version 14.0.0
Version 14.1.0
Oracle
Version 12.0.0
Version 12.1.0
From 3.0 to 3.0.2
Oracle
From 16.2.0 to 16.2.11
From 17.12.0 to 17.12.7
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
Version 19.12
Oracle
Version 12.1
Version 12.2
Version 3.2.1.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 15.0.3
Version 16.0.3
Oracle
Version 14.0
Version 14.1
Oracle
Version 15.0
Version 16.0.3.0
Version 16.0
Version 19.0.1
Oracle
Version 14.0
Version 14.1
Oracle
Version 1.10
Version 1.9
Oracle
Version 13.2.5
Version 13.2.8
Oracle
Version 14.1.3.2
Version 15.0.4.0
Version 15.0
Version 16.0.3.0
Version 16.0
Oracle
Version 14.1.3.2
Version 14.1
Version 15.0.4.0
Version 15.0
Version 16.0.3.0
Version 16.0
Version 19.0.1.0
Version 15.0.3
Version 15.0.3
Version 15.0.3
Version 19.0.1
Oracle
Version 14.0
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 14.0.3
Version 14.1.3
Version 15.0.3
Version 16.0.3.0
Version 16.0.3
Oracle
Version 15.0.3
Version 16.0.3
Version 15.0.3
Oracle
Version 14.0
Version 14.1
Oracle
Version 14.1.3.2
Version 15.0.4.0
Version 15.0
Version 16.0.3.0
Version 16.0
Version 19.0.1.0
Oracle
Version 15.0.3
Version 16.0.3
Oracle
Version 14.0.4
Version 14.1.3
Version 14.1
Version 15.0.3
Version 15.0
Version 16.0.3
Version 16.0
Oracle
Version 15.0.4
Version 16.0.6
Version 17.0.4
Version 18.0.3
Version 19.0.2
Oracle
Before 11.2.2.8.27
Version 11.2.2.8.49
Oracle
From 4.3.0.1.0 to 4.3.0.6.0
Version 2.2.0.0.0
Version 4.2.0.2.0
Version 4.2.0.3.0
Version 4.4.0.0.0
Version 4.4.0.2.0

References (104)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.