CVE-2020-11979
Vulnerability Summary
Timeline
Description
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 1.10%• Percentile: 78%
Techniques & Countermeasures
- CWE-379•Creation of Temporary File in Directory with Insecure Permissions
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.
Affected Systems
- apache•ant
1.10.8
- fedoraproject•fedora
31 | 32 | 33
- gradle•gradle
< 6.8.0
- org.apache.ant•ant
< 1.10.9
- oracle•agile_engineering_data_management
6.2.1.0
- oracle•api_gateway
11.1.2.4.0
- oracle•banking_platform
2.4.0 | 2.4.1 | 2.6.2 | 2.7.0 | 2.7.1 | 2.8.0
- oracle•banking_treasury_management
14.4
- oracle•communications_unified_inventory_management
7.4.0 | 7.4.1
- oracle•data_integrator
12.2.1.3.0 | 12.2.1.4.0
- oracle•endeca_information_discovery_studio
3.2.0.0
- oracle•enterprise_repository
11.1.1.7.0
- oracle•financial_services_analytical_applications_infrastructure
≥ 8.0.6, ≤ 8.0.9 | 8.1.0 | 8.1.1
- oracle•flexcube_private_banking
12.0.0 | 12.1.0
- oracle•primavera_gateway
≥ 16.2.0, ≤ 16.2.11 | ≥ 17.12.0, ≤ 17.12.9
- oracle•primavera_unifier
≥ 17.7, ≤ 17.12 | 16.1 | 16.2 | 18.8 | 19.12 | 20.12
- oracle•real-time_decision_server
3.2.0.0 | 11.1.1.9.0
- oracle•retail_advanced_inventory_planning
14.1
- oracle•retail_assortment_planning
16.0.3
- oracle•retail_category_management_planning_\&_optimization
16.0.3
- oracle•retail_eftlink
19.0.1 | 20.0.0
- oracle•retail_financial_integration
14.1.3 | 15.0.3 | 16.0.3
- oracle•retail_integration_bus
15.0.3
- oracle•retail_item_planning
16.0.3
- oracle•retail_macro_space_optimization
16.0.3
- oracle•retail_merchandise_financial_planning
16.0.3
- oracle•retail_merchandising_system
14.1.3.2 | 16.0.3
- oracle•retail_predictive_application_server
14.1
- oracle•retail_regular_price_optimization
16.0.3
- oracle•retail_replenishment_optimization
16.0.3
- oracle•retail_service_backbone
14.1.3 | 15.0.3 | 16.0.3
- oracle•retail_size_profile_optimization
16.0.3
- oracle•retail_store_inventory_management
14.1.3.9 | 15.0.3.0 | 16.0.3.0
- oracle•retail_xstore_point_of_service
15.0.4 | 16.0.6 | 17.0.4 | 18.0.3 | 19.0.2
- oracle•storagetek_acsls
8.5.1
- oracle•storagetek_tape_analytics
2.4
- oracle•timesten_in-memory_database
< 11.2.2.8.27
- oracle•utilities_framework
4.3.0.5.0 | 4.3.0.6.0 | 4.4.0.0.0 | 4.4.0.2.0
References (32)
- https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E
- https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/
- https://security.gentoo.org/glsa/202011-18
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm
- https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://nvd.nist.gov/vuln/detail/CVE-2020-11979
- https://github.com/apache/ant/commit/87ac51d3c22bcf7cfd0dc07cb0bd04a496e0d428
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI
- https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc@%3Cdev.creadur.apache.org%3E
- https://github.com/apache/ant