Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f62v-xpxf-3v68

Опубликовано: 03 фев. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Code injection in Apache Ant

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Ссылки

Пакеты

Наименование

org.apache.ant:ant

maven
Затронутые версииВерсия исправления

< 1.10.9

1.10.9

EPSS

Процентиль: 94%
0.08235
Низкий

7.5 High

CVSS3

Дефекты

CWE-74
CWE-94

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 6.2
redhat
почти 6 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 7.5
nvd
почти 6 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 7.5
msrc
почти 6 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 7.5
debian
почти 6 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissi ...

EPSS

Процентиль: 94%
0.08235
Низкий

7.5 High

CVSS3

Дефекты

CWE-74
CWE-94