CVE Feed

    Dashboard / CVE / CVE-2020-11979

    CVE-2020-11979

    As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

    Published:Oct 1, 2020
    Last Modified:Nov 21, 2024
    EPS:Oct 1, 2020
    EPSS Score:0.00827
    CVSS Score:7.5

    Affected Products

    Vendor
    Apache
    Product
    Ant
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Gradle
    Product
    Gradle
    Vendor
    Oracle
    Product
    Agile Engineering Data Management
    Vendor
    Oracle
    Product
    Api Gateway
    Vendor
    Oracle
    Product
    Banking Platform
    Vendor
    Oracle
    Product
    Banking Treasury Management
    Vendor
    Oracle
    Product
    Communications Unified Inventory Management
    Vendor
    Oracle
    Product
    Data Integrator
    Vendor
    Oracle
    Product
    Endeca Information Discovery Studio
    Vendor
    Oracle
    Product
    Enterprise Repository
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Flexcube Private Banking
    Vendor
    Oracle
    Product
    Primavera Gateway
    Vendor
    Oracle
    Product
    Primavera Unifier
    Vendor
    Oracle
    Product
    Real-time Decision Server
    Vendor
    Oracle
    Product
    Retail Advanced Inventory Planning
    Vendor
    Oracle
    Product
    Retail Assortment Planning
    Vendor
    Oracle
    Product
    Retail Category Management Planning \& Optimization
    Vendor
    Oracle
    Product
    Retail Eftlink
    Vendor
    Oracle
    Product
    Retail Financial Integration
    Vendor
    Oracle
    Product
    Retail Integration Bus
    Vendor
    Oracle
    Product
    Retail Item Planning
    Vendor
    Oracle
    Product
    Retail Macro Space Optimization
    Vendor
    Oracle
    Product
    Retail Merchandise Financial Planning
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Predictive Application Server
    Vendor
    Oracle
    Product
    Retail Regular Price Optimization
    Vendor
    Oracle
    Product
    Retail Replenishment Optimization
    Vendor
    Oracle
    Product
    Retail Service Backbone
    Vendor
    Oracle
    Product
    Retail Size Profile Optimization
    Vendor
    Oracle
    Product
    Retail Store Inventory Management
    Vendor
    Oracle
    Product
    Retail Xstore Point Of Service
    Vendor
    Oracle
    Product
    Storagetek Acsls
    Vendor
    Oracle
    Product
    Storagetek Tape Analytics
    Vendor
    Oracle
    Product
    Timesten In-memory Database
    Vendor
    Oracle
    Product
    Utilities Framework
    Vendor
    Redhat
    Product
    Openshift

    Exploits

    No exploit reference

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High