SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11979

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them.

HIGH 7.5EPSS 8.02%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (8.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
8.02% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-379
Affected
apache/ant · gradle/gradle · fedoraproject/fedora · oracle/agile engineering data management · oracle/api gateway · oracle/banking platform · oracle/banking treasury management · oracle/communications unified inventory management · oracle/data integrator · oracle/endeca information discovery studio · oracle/enterprise repository · oracle/financial services analytical applications infrastructure · oracle/flexcube private banking · oracle/primavera gateway · oracle/primavera unifier · oracle/real-time decision server · oracle/retail advanced inventory planning · oracle/retail assortment planning · oracle/retail category management planning \& optimization · oracle/retail eftlink · +17 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.