CVE-2020-11979
Last modified
CVE-2020-11979 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. EPSS estimates a 8.14% chance of exploitation in the next 30 days.
Description
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ant | 1.10.8 |
| Gradle | Gradle | < 6.8.0 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Fedoraproject | Fedora | 33 |
| Oracle | Agile Engineering Data Management | 6.2.1.0 |
| Oracle | Api Gateway | 11.1.2.4.0 |
| Oracle | Banking Platform | 2.4.0 |
| Oracle | Banking Platform | 2.4.1 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Banking Platform | 2.7.0 |
| Oracle | Banking Platform | 2.7.1 |
| Oracle | Banking Platform | 2.8.0 |
| Oracle | Banking Treasury Management | 14.4 |
| Oracle | Communications Unified Inventory Management | 7.4.0 |
| Oracle | Communications Unified Inventory Management | 7.4.1 |
| Oracle | Data Integrator | 12.2.1.3.0 |
| Oracle | Data Integrator | 12.2.1.4.0 |
| Oracle | Endeca Information Discovery Studio | 3.2.0.0 |
| Oracle | Enterprise Repository | 11.1.1.7.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6, <= 8.0.9 |
| Oracle | Financial Services Analytical Applications Infrastructure | 8.1.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | 8.1.1 |
| Oracle | Flexcube Private Banking | 12.0.0 |
| Oracle | Flexcube Private Banking | 12.1.0 |
| Oracle | Primavera Gateway | >= 16.2.0, <= 16.2.11 |
| Oracle | Primavera Gateway | >= 17.12.0, <= 17.12.9 |
| Oracle | Primavera Unifier | >= 17.7, <= 17.12 |
| Oracle | Primavera Unifier | 16.1 |
| Oracle | Primavera Unifier | 16.2 |
| Oracle | Primavera Unifier | 18.8 |
| Oracle | Primavera Unifier | 19.12 |
| Oracle | Primavera Unifier | 20.12 |
| Oracle | Real-Time Decision Server | 3.2.0.0 |
| Oracle | Real-Time Decision Server | 11.1.1.9.0 |
| Oracle | Retail Advanced Inventory Planning | 14.1 |
| Oracle | Retail Assortment Planning | 16.0.3 |
| Oracle | Retail Category Management Planning \& Optimization | 16.0.3 |
| Oracle | Retail Eftlink | 19.0.1 |
| Oracle | Retail Eftlink | 20.0.0 |
| Oracle | Retail Financial Integration | 14.1.3 |
| Oracle | Retail Financial Integration | 15.0.3 |
| Oracle | Retail Financial Integration | 16.0.3 |
| Oracle | Retail Integration Bus | 15.0.3 |
| Oracle | Retail Item Planning | 16.0.3 |
| Oracle | Retail Macro Space Optimization | 16.0.3 |
| Oracle | Retail Merchandise Financial Planning | 16.0.3 |
| Oracle | Retail Merchandising System | 14.1.3.2 |
| Oracle | Retail Merchandising System | 16.0.3 |
| Oracle | Retail Predictive Application Server | 14.1 |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vmThird Party Advisory
- https://security.gentoo.org/glsa/202011-18Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vmThird Party Advisory
- https://security.gentoo.org/glsa/202011-18Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11979?
How severe is CVE-2020-11979?
How do I fix CVE-2020-11979?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-11973Apache Camel Netty enables Java deserialization by default. …9.8
- CVE-2020-11974In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a…9.8
- CVE-2020-11975Apache Unomi allows conditions to use OGNL scripting which o…9.8
- CVE-2020-11976By crafting a special URL it is possible to make Wicket deli…7.5
- CVE-2020-11977In Apache Syncope 2.1.X releases prior to 2.1.7, when the Fl…7.2
- CVE-2020-11978An issue was found in Apache Airflow versions 1.10.10 and be…8.8
- CVE-2020-1198<p>A cross-site-scripting (XSS) vulnerability exists when Mi…7.4
- CVE-2020-11980In Karaf, JMX authentication takes place using JAAS and auth…6.3
- CVE-2020-11981An issue was found in Apache Airflow versions 1.10.10 and be…9.8
- CVE-2020-11982An issue was found in Apache Airflow versions 1.10.10 and be…9.8
- CVE-2020-11983An issue was found in Apache Airflow versions 1.10.10 and be…5.4
- CVE-2020-11984Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info dis…9.8
Are you affected by CVE-2020-11979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
