CVE-2020-1945
Published on: 05/14/2020 12:00:00 AM UTC
Last Modified on: 04/04/2022 01:31:00 PM UTC
Certain versions of Ant from Apache contain the following vulnerability:
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
- CVE-2020-1945 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | NONE |
CVSS2 Score: 3.3 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | NONE |
CVE References
Related QID Numbers
- 296073 Oracle Solaris 11.4 Support Repository Update (SRU) 24.75.2 Missing (CPUJUL2020)
- 501175 Alpine Linux Security Update for apache-ant
- 690501 Free Berkeley Software Distribution (FreeBSD) Security Update for apache ant leaks sensitive information via the java.io.tmpdir (6d5f1b0b-b865-48d5-935b-3fb6ebb425fc)
- 752811 SUSE Enterprise Linux Security Update for ant (SUSE-SU-2022:4022-1)
- 770050 Red Hat OpenShift Container Platform Security and Packages Update 4.6.17 (RHSA-2021:0423)
- 770051 Red Hat OpenShift Container Platform 4.5.33 Packages and Security Update (RHSA-2021:0429)
- 770099 Red Hat OpenShift Container Platform 4.5 Security Update (RHSA-2021-0429)
- 770122 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021-0423)
- 980315 Java (maven) Security Update for org.apache.ant:ant (GHSA-4p6w-m9wc-c9c9)
Known Affected Configurations (CPE V2.3)
- cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*:
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*:
- cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_collections:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_liquidity_management:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:category_management_planning_\&_optimization:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_asap:7.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_metasolv_solution:6.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_order_and_service_management:7.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_order_and_service_management:7.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_investor_servicing:14.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_investor_servicing:14.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:health_sciences_information_manager:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:real-time_decision_server:3.2.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_advanced_inventory_planning:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_assortment_planning:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_assortment_planning:16.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_back_office:14.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_bulk_data_integration:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_bulk_data_integration:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_bulk_data_integration:19.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_central_office:14.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_data_extractor_for_merchandising:1.10:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_data_extractor_for_merchandising:1.9:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.5:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_extract_transform_and_load:13.2.8:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_financial_integration:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_financial_integration:15.0.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_financial_integration:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_financial_integration:16.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:15.0.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:16.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_integration_bus:19.0.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_item_planning:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_macro_space_optimization:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_merchandise_financial_planning:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_point-of-service:14.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_point-of-service:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_point-of-service:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_predictive_application_server:14.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_regular_price_optimization:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_regular_price_optimization:16.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_replenishment_optimization:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_returns_management:14.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_service_backbone:15.0.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_service_backbone:16.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_service_backbone:19.0.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_size_profile_optimization:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_size_profile_optimization:16.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:14.0.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:14.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:14.1.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:15.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:16.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_store_inventory_management:16.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:15.0.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:timesten_in-memory_database:11.2.2.8.49:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:utilities_framework:2.2.0.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:utilities_framework:4.2.0.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:utilities_framework:4.2.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:utilities_framework:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|