Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11979

Опубликовано: 01 окт. 2020
Источник: redhat
CVSS3: 6.2

Описание

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Отчет

ant as shipped in Red Hat Enterprise Linux 8 is not affected by this flaw because this flaw is caused by the patch for CVE-2020-1945, however, it was never applied to ant as shipped in Red Hat Enterprise Linux 8, because the decision was made by Engineering to WONTFIX that flaw. In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of ant package. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6antOut of support scope
Red Hat CodeReady Studio 12antAffected
Red Hat Decision Manager 7antWill not fix
Red Hat Enterprise Linux 5antOut of support scope
Red Hat Enterprise Linux 6antOut of support scope
Red Hat Enterprise Linux 7antOut of support scope
Red Hat Enterprise Linux 8antNot affected
Red Hat Enterprise Linux 8ant:1.10/antNot affected
Red Hat JBoss BRMS 5antOut of support scope
Red Hat JBoss Data Virtualization 6antOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 7.5
nvd
больше 5 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 7.5
msrc
больше 5 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS3: 7.5
debian
больше 5 лет назад

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissi ...

CVSS3: 7.5
github
около 5 лет назад

Code injection in Apache Ant

6.2 Medium

CVSS3

Уязвимость CVE-2020-11979