CVE-2020-11979
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Published:Oct 1, 2020
Last Modified:Nov 21, 2024
EPS:Oct 1, 2020
EPSS Score:0.00827
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Ant
Apache
Ant
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Gradle
Product
Gradle
Gradle
Gradle
Vendor
Oracle
Product
Agile Engineering Data Management
Oracle
Agile Engineering Data Management
Vendor
Oracle
Product
Api Gateway
Oracle
Api Gateway
Vendor
Oracle
Product
Banking Platform
Oracle
Banking Platform
Vendor
Oracle
Product
Banking Treasury Management
Oracle
Banking Treasury Management
Vendor
Oracle
Product
Communications Unified Inventory Management
Oracle
Communications Unified Inventory Management
Vendor
Oracle
Product
Data Integrator
Oracle
Data Integrator
Vendor
Oracle
Product
Endeca Information Discovery Studio
Oracle
Endeca Information Discovery Studio
Vendor
Oracle
Product
Enterprise Repository
Oracle
Enterprise Repository
Vendor
Oracle
Product
Financial Services Analytical Applications Infrastructure
Oracle
Financial Services Analytical Applications Infrastructure
Vendor
Oracle
Product
Flexcube Private Banking
Oracle
Flexcube Private Banking
Vendor
Oracle
Product
Primavera Gateway
Oracle
Primavera Gateway
Vendor
Oracle
Product
Primavera Unifier
Oracle
Primavera Unifier
Vendor
Oracle
Product
Real-time Decision Server
Oracle
Real-time Decision Server
Vendor
Oracle
Product
Retail Advanced Inventory Planning
Oracle
Retail Advanced Inventory Planning
Vendor
Oracle
Product
Retail Assortment Planning
Oracle
Retail Assortment Planning
Vendor
Oracle
Product
Retail Category Management Planning \& Optimization
Oracle
Retail Category Management Planning \& Optimization
Vendor
Oracle
Product
Retail Eftlink
Oracle
Retail Eftlink
Vendor
Oracle
Product
Retail Financial Integration
Oracle
Retail Financial Integration
Vendor
Oracle
Product
Retail Integration Bus
Oracle
Retail Integration Bus
Vendor
Oracle
Product
Retail Item Planning
Oracle
Retail Item Planning
Vendor
Oracle
Product
Retail Macro Space Optimization
Oracle
Retail Macro Space Optimization
Vendor
Oracle
Product
Retail Merchandise Financial Planning
Oracle
Retail Merchandise Financial Planning
Vendor
Oracle
Product
Retail Merchandising System
Oracle
Retail Merchandising System
Vendor
Oracle
Product
Retail Predictive Application Server
Oracle
Retail Predictive Application Server
Vendor
Oracle
Product
Retail Regular Price Optimization
Oracle
Retail Regular Price Optimization
Vendor
Oracle
Product
Retail Replenishment Optimization
Oracle
Retail Replenishment Optimization
Vendor
Oracle
Product
Retail Service Backbone
Oracle
Retail Service Backbone
Vendor
Oracle
Product
Retail Size Profile Optimization
Oracle
Retail Size Profile Optimization
Vendor
Oracle
Product
Retail Store Inventory Management
Oracle
Retail Store Inventory Management
Vendor
Oracle
Product
Retail Xstore Point Of Service
Oracle
Retail Xstore Point Of Service
Vendor
Oracle
Product
Storagetek Acsls
Oracle
Storagetek Acsls
Vendor
Oracle
Product
Storagetek Tape Analytics
Oracle
Storagetek Tape Analytics
Vendor
Oracle
Product
Timesten In-memory Database
Oracle
Timesten In-memory Database
Vendor
Oracle
Product
Utilities Framework
Oracle
Utilities Framework
Vendor
Redhat
Product
Openshift
Redhat
Openshift
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
