MEDIUM · 6.3

CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The ...

Vulnerability Description

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
ApacheAnt>= 1.1, <= 1.9.14
CanonicalUbuntu Linux19.10
FedoraprojectFedora31
OpensuseLeap15.2
OracleAgile Engineering Data Management6.2.1.0
OracleBanking Enterprise Collections>= 2.7.0, <= 2.9.0
OracleBanking Liquidity Management>= 14.0.0, <= 14.4.0
OracleBanking Platform>= 2.4.0, <= 2.9.0
OracleBusiness Process Management Suite12.2.1.3.0
OracleCategory Management Planning \& Optimization15.0.3
OracleCommunications Asap7.3
OracleCommunications Diameter Signaling Router>= 8.0.0, <= 8.2.2
OracleCommunications Metasolv Solution6.3.0
OracleCommunications Order And Service Management7.3
OracleData Integrator12.2.1.3.0
OracleEndeca Information Discovery Studio3.2.0
OracleEnterprise Manager Ops Center12.4.0.0
OracleEnterprise Repository11.1.1.7.0
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.6, <= 8.1.0
OracleFlexcube Investor Servicing12.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-1945?

CVE-2020-1945 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The ...

How severe is CVE-2020-1945?

CVE-2020-1945 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-1945?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Ant, Canonical Ubuntu Linux, Fedoraproject Fedora, Opensuse Leap, Oracle Agile Engineering Data Management.