CVE-2020-11979
Last modified
CVE-2020-11979 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. EPSS estimates a 8.14% chance of exploitation in the next 30 days.
Description
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ant | 1.10.8 |
| Gradle | Gradle | < 6.8.0 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Fedoraproject | Fedora | 33 |
| Oracle | Agile Engineering Data Management | 6.2.1.0 |
| Oracle | Api Gateway | 11.1.2.4.0 |
| Oracle | Banking Platform | 2.4.0 |
| Oracle | Banking Platform | 2.4.1 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Banking Platform | 2.7.0 |
| Oracle | Banking Platform | 2.7.1 |
| Oracle | Banking Platform | 2.8.0 |
| Oracle | Banking Treasury Management | 14.4 |
| Oracle | Communications Unified Inventory Management | 7.4.0 |
| Oracle | Communications Unified Inventory Management | 7.4.1 |
| Oracle | Data Integrator | 12.2.1.3.0 |
| Oracle | Data Integrator | 12.2.1.4.0 |
| Oracle | Endeca Information Discovery Studio | 3.2.0.0 |
| Oracle | Enterprise Repository | 11.1.1.7.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | >= 8.0.6, <= 8.0.9 |
| Oracle | Financial Services Analytical Applications Infrastructure | 8.1.0 |
| Oracle | Financial Services Analytical Applications Infrastructure | 8.1.1 |
| Oracle | Flexcube Private Banking | 12.0.0 |
| Oracle | Flexcube Private Banking | 12.1.0 |
| Oracle | Primavera Gateway | >= 16.2.0, <= 16.2.11 |
| Oracle | Primavera Gateway | >= 17.12.0, <= 17.12.9 |
| Oracle | Primavera Unifier | >= 17.7, <= 17.12 |
| Oracle | Primavera Unifier | 16.1 |
| Oracle | Primavera Unifier | 16.2 |
| Oracle | Primavera Unifier | 18.8 |
| Oracle | Primavera Unifier | 19.12 |
| Oracle | Primavera Unifier | 20.12 |
| Oracle | Real-Time Decision Server | 3.2.0.0 |
| Oracle | Real-Time Decision Server | 11.1.1.9.0 |
| Oracle | Retail Advanced Inventory Planning | 14.1 |
| Oracle | Retail Assortment Planning | 16.0.3 |
| Oracle | Retail Category Management Planning \& Optimization | 16.0.3 |
| Oracle | Retail Eftlink | 19.0.1 |
| Oracle | Retail Eftlink | 20.0.0 |
| Oracle | Retail Financial Integration | 14.1.3 |
| Oracle | Retail Financial Integration | 15.0.3 |
| Oracle | Retail Financial Integration | 16.0.3 |
| Oracle | Retail Integration Bus | 15.0.3 |
| Oracle | Retail Item Planning | 16.0.3 |
| Oracle | Retail Macro Space Optimization | 16.0.3 |
| Oracle | Retail Merchandise Financial Planning | 16.0.3 |
| Oracle | Retail Merchandising System | 14.1.3.2 |
| Oracle | Retail Merchandising System | 16.0.3 |
| Oracle | Retail Predictive Application Server | 14.1 |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vmThird Party Advisory
- https://security.gentoo.org/glsa/202011-18Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vmThird Party Advisory
- https://security.gentoo.org/glsa/202011-18Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11979?
How severe is CVE-2020-11979?
How do I fix CVE-2020-11979?
Are you affected by CVE-2020-11979?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
