Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1945

Опубликовано: 14 мая 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.3
CVSS3: 6.3

Описание

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.10.8-1
eoan

released

1.10.6-1ubuntu0.1
esm-apps/bionic

released

1.10.5-3~18.04.1~esm1
esm-apps/focal

released

1.10.7-1ubuntu0.1~esm1
esm-apps/jammy

not-affected

1.10.8-1
esm-apps/noble

not-affected

1.10.8-1
esm-apps/xenial

released

1.9.6-1ubuntu1.1+esm1
esm-infra-legacy/trusty

released

1.9.3-2ubuntu0.1+esm1
focal

ignored

end of standard support, was needed

Показывать по

EPSS

Процентиль: 5%
0.00021
Низкий

3.3 Low

CVSS2

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

CVSS3: 6.3
nvd
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

CVSS3: 6.3
debian
больше 5 лет назад

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default tempora ...

suse-cvrf
больше 5 лет назад

Security update for ant

suse-cvrf
больше 5 лет назад

Security update for ant

EPSS

Процентиль: 5%
0.00021
Низкий

3.3 Low

CVSS2

6.3 Medium

CVSS3