Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Ant
Subscribe
|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
Agile Engineering Data Management
Subscribe
Banking Enterprise Collections
Subscribe
Banking Liquidity Management
Subscribe
Banking Platform
Subscribe
Business Process Management Suite
Subscribe
Category Management Planning \& Optimization
Subscribe
Communications Asap
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Metasolv Solution
Subscribe
Communications Order And Service Management
Subscribe
Data Integrator
Subscribe
Endeca Information Discovery Studio
Subscribe
Enterprise Manager Ops Center
Subscribe
Enterprise Repository
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Investor Servicing
Subscribe
Flexcube Private Banking
Subscribe
Health Sciences Information Manager
Subscribe
Primavera Gateway
Subscribe
Primavera Unifier
Subscribe
Rapid Planning
Subscribe
Real-time Decision Server
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Assortment Planning
Subscribe
Retail Back Office
Subscribe
Retail Bulk Data Integration
Subscribe
Retail Central Office
Subscribe
Retail Data Extractor For Merchandising
Subscribe
Retail Extract Transform And Load
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Item Planning
Subscribe
Retail Macro Space Optimization
Subscribe
Retail Merchandise Financial Planning
Subscribe
Retail Merchandising System
Subscribe
Retail Point-of-service
Subscribe
Retail Predictive Application Server
Subscribe
Retail Regular Price Optimization
Subscribe
Retail Replenishment Optimization
Subscribe
Retail Returns Management
Subscribe
Retail Service Backbone
Subscribe
Retail Size Profile Optimization
Subscribe
Retail Store Inventory Management
Subscribe
Retail Xstore Point Of Service
Subscribe
Timesten In-memory Database
Subscribe
Utilities Framework
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0743 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process. |
Github GHSA |
GHSA-4p6w-m9wc-c9c9 | Sensitive Data Exposure in Apache Ant |
Ubuntu USN |
USN-4380-1 | Apache Ant vulnerability |
Ubuntu USN |
USN-4874-1 | Apache Ant vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T06:54:00.377Z
Reserved: 2019-12-02T00:00:00
Link: CVE-2020-1945
No data.
Status : Modified
Published: 2020-05-14T16:15:12.767
Modified: 2024-11-21T05:11:42.183
Link: CVE-2020-1945
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN