As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Ant
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Gradle
Subscribe
|
Gradle
Subscribe
|
|
Oracle
Subscribe
|
Agile Engineering Data Management
Subscribe
Api Gateway
Subscribe
Banking Platform
Subscribe
Banking Treasury Management
Subscribe
Communications Unified Inventory Management
Subscribe
Data Integrator
Subscribe
Endeca Information Discovery Studio
Subscribe
Enterprise Repository
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Private Banking
Subscribe
Primavera Gateway
Subscribe
Primavera Unifier
Subscribe
Real-time Decision Server
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Assortment Planning
Subscribe
Retail Category Management Planning \& Optimization
Subscribe
Retail Eftlink
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Item Planning
Subscribe
Retail Macro Space Optimization
Subscribe
Retail Merchandise Financial Planning
Subscribe
Retail Merchandising System
Subscribe
Retail Predictive Application Server
Subscribe
Retail Regular Price Optimization
Subscribe
Retail Replenishment Optimization
Subscribe
Retail Service Backbone
Subscribe
Retail Size Profile Optimization
Subscribe
Retail Store Inventory Management
Subscribe
Retail Xstore Point Of Service
Subscribe
Storagetek Acsls
Subscribe
Storagetek Tape Analytics
Subscribe
Timesten In-memory Database
Subscribe
Utilities Framework
Subscribe
|
|
Redhat
Subscribe
|
Openshift
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0549 | Code injection in Apache Ant |
Github GHSA |
GHSA-f62v-xpxf-3v68 | Code injection in Apache Ant |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T11:48:57.549Z
Reserved: 2020-04-21T00:00:00
Link: CVE-2020-11979
No data.
Status : Modified
Published: 2020-10-01T20:15:13.033
Modified: 2024-11-21T04:59:02.170
Link: CVE-2020-11979
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA