CVE-2020-11979

HIGH

Apache Ant <1.10.8 - Code Injection

Title source: llm
STIX 2.1

Description

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

References (19)

Core 19
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202011-18
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 7.5
EPSS 0.0110
EPSS Percentile 78.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-379
Status published
Products (50)
apache/ant 1.10.8
fedoraproject/fedora 31
fedoraproject/fedora 32
fedoraproject/fedora 33
gradle/gradle < 6.8.0
oracle/agile_engineering_data_management 6.2.1.0
oracle/api_gateway 11.1.2.4.0
oracle/banking_platform 2.4.0
oracle/banking_platform 2.4.1
oracle/banking_platform 2.6.2
... and 40 more
Published Oct 01, 2020
Tracked Since Feb 18, 2026