7.5

CVE-2020-11979

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Ant Version 1.10.8
Gradle ≫ Gradle Version < 6.8.0
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Oracle ≫ Api Gateway Version 11.1.2.4.0
Oracle ≫ Banking Platform Version 2.4.0
Oracle ≫ Banking Platform Version 2.4.1
Oracle ≫ Banking Platform Version 2.6.2
Oracle ≫ Banking Platform Version 2.7.0
Oracle ≫ Banking Platform Version 2.7.1
Oracle ≫ Banking Platform Version 2.8.0
Oracle ≫ Data Integrator Version 12.2.1.3.0
Oracle ≫ Data Integrator Version 12.2.1.4.0
Oracle ≫ Enterprise Repository Version 11.1.1.7.0
Oracle ≫ Flexcube Private Banking Version 12.0.0
Oracle ≫ Flexcube Private Banking Version 12.1.0
Oracle ≫ Primavera Gateway Version >= 16.2.0 <= 16.2.11
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.9
Oracle ≫ Primavera Unifier Version >= 17.7 <= 17.12
Oracle ≫ Primavera Unifier Version 16.1
Oracle ≫ Primavera Unifier Version 16.2
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Primavera Unifier Version 19.12
Oracle ≫ Primavera Unifier Version 20.12
Oracle ≫ Real-time Decision Server Version 3.2.0.0
Oracle ≫ Real-time Decision Server Version 11.1.1.9.0
Oracle ≫ Retail Assortment Planning Version 16.0.3
Oracle ≫ Retail Eftlink Version 19.0.1
Oracle ≫ Retail Eftlink Version 20.0.0
Oracle ≫ Retail Integration Bus Version 15.0.3
Oracle ≫ Retail Item Planning Version 16.0.3
Oracle ≫ Retail Merchandising System Version 14.1.3.2
Oracle ≫ Retail Merchandising System Version 16.0.3
Oracle ≫ Retail Service Backbone Version 14.1.3
Oracle ≫ Retail Service Backbone Version 15.0.3
Oracle ≫ Retail Service Backbone Version 16.0.3
Oracle ≫ Storagetek Acsls Version 8.5.1
Oracle ≫ Timesten In-memory Database Version < 11.2.2.8.27
Oracle ≫ Utilities Framework Version 4.3.0.5.0
Oracle ≫ Utilities Framework Version 4.3.0.6.0
Oracle ≫ Utilities Framework Version 4.4.0.0.0
Oracle ≫ Utilities Framework Version 4.4.0.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.24% 0.942
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-379 Creation of Temporary File in Directory with Insecure Permissions

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2021.html
Patch
Third Party Advisory
https://security.gentoo.org/glsa/202011-18
Third Party Advisory
https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm
Third Party Advisory
https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E
https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E
Vendor Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/