CVE-2020-1945

MEDIUM

Apache Ant 1.1-1.9.14 and 1.10.0-1.10.7 - Information Disclosure and Arbitrary File Write via Temporary Directory

Title source: llm
STIX 2.1

Description

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

References (52)

Core 52
Core References
Mailing List, Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4380-1/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00053.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202007-34
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/09/30/6
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/12/06/1
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html

Scores

CVSS v3 6.3
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-668
Status published
Products (50)
apache/ant 1.1 - 1.9.14
canonical/ubuntu_linux 19.10
fedoraproject/fedora 31
fedoraproject/fedora 32
opensuse/leap 15.2
oracle/agile_engineering_data_management 6.2.1.0
oracle/banking_enterprise_collections 2.7.0 - 2.9.0
oracle/banking_liquidity_management 14.0.0 - 14.4.0
oracle/banking_platform 2.4.0 - 2.9.0
oracle/business_process_management_suite 12.2.1.3.0
... and 40 more
Published May 14, 2020
Tracked Since Feb 18, 2026