HIGH · 7.5

CVE-2020-11979

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted...

Vulnerability Description

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
ApacheAnt1.10.8
GradleGradle< 6.8.0
FedoraprojectFedora31
OracleAgile Engineering Data Management6.2.1.0
OracleApi Gateway11.1.2.4.0
OracleBanking Platform2.4.0
OracleBanking Treasury Management14.4
OracleCommunications Unified Inventory Management7.4.0
OracleData Integrator12.2.1.3.0
OracleEndeca Information Discovery Studio3.2.0.0
OracleEnterprise Repository11.1.1.7.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.0.9
OracleFlexcube Private Banking12.0.0
OraclePrimavera Gateway>= 16.2.0, <= 16.2.11
OraclePrimavera Unifier>= 17.7, <= 17.12
OracleReal-Time Decision Server3.2.0.0
OracleRetail Advanced Inventory Planning14.1
OracleRetail Assortment Planning16.0.3
OracleRetail Category Management Planning \& Optimization16.0.3
OracleRetail Eftlink19.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11979?

CVE-2020-11979 is a vulnerability with a CVSS score of 7.5 (HIGH). As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted...

How severe is CVE-2020-11979?

CVE-2020-11979 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11979?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Ant, Gradle Gradle, Fedoraproject Fedora, Oracle Agile Engineering Data Management, Oracle Api Gateway.