As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache-antUpgrade gradle | Aug 22, 2024 | Oct 1, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 1, 2020 |
| Debian | — | Upgrade ant | Jul 30, 2024 | Oct 1, 2020 |
| Gentoo Linux | — | Upgrade dev-java/ant. | Nov 17, 2020 | Oct 1, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade antUpgrade ant-lib | Feb 2, 2021 | Oct 1, 2020 |
| Oracle Solaris | — | Upgrade developer/build/ant to version 1.10.9-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Oct 1, 2020 |
| Redhat Openshift | — | Upgrade openshift-clientsUpgrade jenkinsUpgrade openshiftUpgrade machine-config-daemonUpgrade conmonUpgrade openshift-ansibleUpgrade runc | Feb 18, 2021 | Oct 1, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 1, 2020 |
| Suse | — | Upgrade ant-apache-resolverUpgrade ant-junit5Upgrade ant-xzUpgrade antlr3-javaUpgrade antlr4-javaUpgrade maven-antrun-plugin-javadocUpgrade jetty-antUpgrade ant-jmfUpgrade ant-apache-oroUpgrade ant-contrib-javadocUpgrade antlr3-toolUpgrade ant-antlrUpgrade ant-contribUpgrade ant-manualUpgrade maven-script-antUpgrade jsch-agent-proxy-pageantUpgrade antlr3-java-javadocUpgrade maven-antrun-pluginUpgrade maven-plugin-tools-antUpgrade ant-apache-bcelUpgrade plexus-ant-factoryUpgrade ant-jdependUpgrade ant-swingUpgrade antlr-bootstrapUpgrade ant-contrib-manualUpgrade ant-javadocUpgrade antlr3-javadocUpgrade groovy-antUpgrade antlr-javaUpgrade antlr4-toolUpgrade ant-apache-bsfUpgrade ant-scalaUpgrade ant-commons-loggingUpgrade ant-javamailUpgrade ant-testutilUpgrade ant-jschUpgrade ant-apache-regexpUpgrade antlr-develUpgrade antlrUpgrade antlr4-javadocUpgrade libantlr4-runtime-develUpgrade ant-scriptsUpgrade antUpgrade paranamer-antUpgrade ant-commons-netUpgrade plexus-ant-factory-javadocUpgrade antlr3-bootstrap-toolUpgrade ant-junitUpgrade ant-apache-log4jUpgrade antlr-manualUpgrade ant-imageioUpgrade ant-apache-xalan2Upgrade antlr4-maven-plugin | Aug 9, 2024 | Oct 1, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 1, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub