CVE-2020-1945

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
apacheant
1.1 ≤
𝑥
≤ 1.9.14
apacheant
1.10.0 ≤
𝑥
≤ 1.10.7
canonicalubuntu_linux
19.10
opensuseleap
15.2
oracleagile_engineering_data_management
6.2.1.0
oraclebanking_enterprise_collections
2.7.0 ≤
𝑥
≤ 2.9.0
oraclebanking_liquidity_management
14.0.0 ≤
𝑥
≤ 14.4.0
oraclebanking_platform
2.4.0 ≤
𝑥
≤ 2.9.0
oraclebusiness_process_management_suite
12.2.1.3.0
oraclebusiness_process_management_suite
12.2.1.4.0
oraclecategory_management_planning_\&_optimization
15.0.3
oraclecommunications_asap
7.3
oraclecommunications_diameter_signaling_router
8.0.0 ≤
𝑥
≤ 8.2.2
oraclecommunications_metasolv_solution
6.3.0
oraclecommunications_order_and_service_management
7.3
oraclecommunications_order_and_service_management
7.4
oracledata_integrator
12.2.1.3.0
oracledata_integrator
12.2.1.4.0
oracleendeca_information_discovery_studio
3.2.0
oracleenterprise_manager_ops_center
12.4.0.0
oracleenterprise_repository
11.1.1.7.0
oraclefinancial_services_analytical_applications_infrastructure
8.0.6 ≤
𝑥
≤ 8.1.0
oracleflexcube_investor_servicing
12.1.0
oracleflexcube_investor_servicing
12.3.0
oracleflexcube_investor_servicing
12.4.0
oracleflexcube_investor_servicing
14.0.0
oracleflexcube_investor_servicing
14.1.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehealth_sciences_information_manager
3.0 ≤
𝑥
≤ 3.0.2
oracleprimavera_gateway
16.2.0 ≤
𝑥
≤ 16.2.11
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.7
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
16.1
oracleprimavera_unifier
16.2
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oraclereal-time_decision_server
3.2.1.0
oracleretail_advanced_inventory_planning
14.1
oracleretail_advanced_inventory_planning
15.0
oracleretail_advanced_inventory_planning
16.0
oracleretail_assortment_planning
15.0.3
oracleretail_assortment_planning
16.0.3
oracleretail_back_office
14.0
oracleretail_back_office
14.1
oracleretail_bulk_data_integration
15.0
oracleretail_bulk_data_integration
16.0
oracleretail_bulk_data_integration
16.0.3.0
oracleretail_bulk_data_integration
19.0.1
oracleretail_central_office
14.0
oracleretail_central_office
14.1
oracleretail_data_extractor_for_merchandising
1.9
oracleretail_data_extractor_for_merchandising
1.10
oracleretail_extract_transform_and_load
13.2.5
oracleretail_extract_transform_and_load
13.2.8
oracleretail_financial_integration
14.1.3.2
oracleretail_financial_integration
15.0
oracleretail_financial_integration
15.0.4.0
oracleretail_financial_integration
16.0
oracleretail_financial_integration
16.0.3.0
oracleretail_integration_bus
14.1
oracleretail_integration_bus
14.1.3.2
oracleretail_integration_bus
15.0
oracleretail_integration_bus
15.0.4.0
oracleretail_integration_bus
16.0
oracleretail_integration_bus
16.0.3.0
oracleretail_integration_bus
19.0.1.0
oracleretail_item_planning
15.0.3
oracleretail_macro_space_optimization
15.0.3
oracleretail_merchandise_financial_planning
15.0.3
oracleretail_merchandising_system
19.0.1
oracleretail_point-of-service
14.0
oracleretail_point-of-service
14.1
oracleretail_point-of-service
15.0
oracleretail_point-of-service
16.0
oracleretail_predictive_application_server
14.0.3
oracleretail_predictive_application_server
14.1.3
oracleretail_predictive_application_server
15.0.3
oracleretail_predictive_application_server
16.0.3
oracleretail_predictive_application_server
16.0.3.0
oracleretail_regular_price_optimization
15.0.3
oracleretail_regular_price_optimization
16.0.3
oracleretail_replenishment_optimization
15.0.3
oracleretail_returns_management
14.0
oracleretail_returns_management
14.1
oracleretail_service_backbone
14.1.3.2
oracleretail_service_backbone
15.0
oracleretail_service_backbone
15.0.4.0
oracleretail_service_backbone
16.0
oracleretail_service_backbone
16.0.3.0
oracleretail_service_backbone
19.0.1.0
oracleretail_size_profile_optimization
15.0.3
oracleretail_size_profile_optimization
16.0.3
oracleretail_store_inventory_management
14.0.4
oracleretail_store_inventory_management
14.1
oracleretail_store_inventory_management
14.1.3
oracleretail_store_inventory_management
15.0
oracleretail_store_inventory_management
15.0.3
oracleretail_store_inventory_management
16.0
oracleretail_store_inventory_management
16.0.3
oracleretail_xstore_point_of_service
15.0.4
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
oracletimesten_in-memory_database
𝑥
< 11.2.2.8.27
oracletimesten_in-memory_database
11.2.2.8.49
oracleutilities_framework
4.3.0.1.0 ≤
𝑥
≤ 4.3.0.6.0
oracleutilities_framework
2.2.0.0.0
oracleutilities_framework
4.2.0.2.0
oracleutilities_framework
4.2.0.3.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ant
bullseye
1.10.9-4
fixed
buster
no-dsa
stretch
no-dsa
jessie
no-dsa
bookworm
1.10.13-1
fixed
sid
1.10.15-1
fixed
trixie
1.10.15-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ant
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
Fixed 1.10.7-1ubuntu0.1~esm1
released
eoan
Fixed 1.10.6-1ubuntu0.1
released
bionic
Fixed 1.10.5-3~18.04.1~esm1
released
xenial
Fixed 1.9.6-1ubuntu1.1+esm1
released
trusty
Fixed 1.9.3-2ubuntu0.1+esm1
released
References