Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4p6w-m9wc-c9c9

Опубликовано: 14 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Sensitive Data Exposure in Apache Ant

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

Ссылки

Пакеты

Наименование

org.apache.ant:ant

maven
Затронутые версииВерсия исправления

>= 1.1, < 1.9.15

1.9.15

Наименование

org.apache.ant:ant

maven
Затронутые версииВерсия исправления

>= 1.10.0, < 1.10.8

1.10.8

EPSS

Процентиль: 5%
0.00021
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-200
CWE-668

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

CVSS3: 6.3
redhat
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

CVSS3: 6.3
nvd
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

CVSS3: 6.3
debian
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default tempora ...

suse-cvrf
больше 5 лет назад

Security update for ant

EPSS

Процентиль: 5%
0.00021
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-200
CWE-668