Vulnerability Intelligence Report
CVE-2020-11979
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
EPSS Probability:8.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-379 ↗CWE-379 Creation of Temporary File in Directory with Incorrect Permissions
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| apache | ant | 1.10.8 |
| gradle | gradle | all |
| fedoraproject | fedora | 31, 32, 33 |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | api_gateway | 11.1.2.4.0 |
| oracle | banking_platform | 2.4.0, 2.4.1, 2.6.2, 2.7.0, 2.7.1, 2.8.0 |
| oracle | banking_treasury_management | 14.4 |
| oracle | communications_unified_inventory_management | 7.4.0, 7.4.1 |
| oracle | data_integrator | 12.2.1.3.0, 12.2.1.4.0 |
| oracle | endeca_information_discovery_studio | 3.2.0.0 |
| oracle | enterprise_repository | 11.1.1.7.0 |
| oracle | financial_services_analytical_applications_infrastructure | 8.1.0, 8.1.1 |
| oracle | flexcube_private_banking | 12.0.0, 12.1.0 |
| oracle | primavera_gateway | all |
| oracle | primavera_unifier | 16.1, 16.2, 18.8, 19.12, 20.12 |
| oracle | real-time_decision_server | 3.2.0.0, 11.1.1.9.0 |
| oracle | retail_advanced_inventory_planning | 14.1 |
| oracle | retail_assortment_planning | 16.0.3 |
| oracle | retail_category_management_planning_\&_optimization | 16.0.3 |
| oracle | retail_eftlink | 19.0.1, 20.0.0 |
| oracle | retail_financial_integration | 14.1.3, 15.0.3, 16.0.3 |
| oracle | retail_integration_bus | 15.0.3 |
| oracle | retail_item_planning | 16.0.3 |
| oracle | retail_macro_space_optimization | 16.0.3 |
| oracle | retail_merchandise_financial_planning | 16.0.3 |
| oracle | retail_merchandising_system | 14.1.3.2, 16.0.3 |
| oracle | retail_predictive_application_server | 14.1 |
| oracle | retail_regular_price_optimization | 16.0.3 |
| oracle | retail_replenishment_optimization | 16.0.3 |
| oracle | retail_service_backbone | 14.1.3, 15.0.3, 16.0.3 |
| oracle | retail_size_profile_optimization | 16.0.3 |
| oracle | retail_store_inventory_management | 14.1.3.9, 15.0.3.0, 16.0.3.0 |
| oracle | retail_xstore_point_of_service | 15.0.4, 16.0.6, 17.0.4, 18.0.3, 19.0.2 |
| oracle | storagetek_acsls | 8.5.1 |
| oracle | storagetek_tape_analytics | 2.4 |
| oracle | timesten_in-memory_database | all |
| oracle | utilities_framework | 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
8.137%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apache Software Foundation · Vendor · USA |
| Reserved | 2020-04-21T00:00:00 |
| Published | 2020-10-01T19:24:57 |
| Last Updated | 2024-08-04T11:48:57 |
Community Chatter & Buzz