7.5

CVE-2020-11979

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAnt Version1.10.8
GradleGradle Version < 6.8.0
FedoraprojectFedora Version31
FedoraprojectFedora Version32
FedoraprojectFedora Version33
OracleApi Gateway Version11.1.2.4.0
OracleBanking Platform Version2.4.0
OracleBanking Platform Version2.4.1
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.0
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.8.0
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleEnterprise Repository Version11.1.1.7.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OraclePrimavera Gateway Version >= 16.2.0 <= 16.2.11
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.9
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OracleReal-time Decision Server Version3.2.0.0
OracleReal-time Decision Server Version11.1.1.9.0
OracleRetail Eftlink Version19.0.1
OracleRetail Eftlink Version20.0.0
OracleRetail Integration Bus Version15.0.3
OracleRetail Item Planning Version16.0.3
OracleRetail Merchandising System Version14.1.3.2
OracleRetail Service Backbone Version14.1.3
OracleRetail Service Backbone Version15.0.3
OracleRetail Service Backbone Version16.0.3
OracleStoragetek Acsls Version8.5.1
OracleTimesten In-memory Database Version < 11.2.2.8.27
OracleUtilities Framework Version4.3.0.5.0
OracleUtilities Framework Version4.3.0.6.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.689
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-379 Creation of Temporary File in Directory with Insecure Permissions

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.