As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade gradleUpgrade apache-ant | Aug 22, 2024 | Oct 1, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 1, 2020 |
| Debian | — | Upgrade ant | Jul 30, 2024 | Oct 1, 2020 |
| Gentoo Linux | — | Upgrade dev-java/ant. | Nov 17, 2020 | Oct 1, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade ant-libUpgrade ant | Feb 2, 2021 | Oct 1, 2020 |
| Oracle Solaris | — | Upgrade developer/build/ant to version 1.10.9-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Oct 1, 2020 |
| Redhat Openshift | — | Upgrade runcUpgrade openshift-clientsUpgrade machine-config-daemonUpgrade jenkinsUpgrade openshiftUpgrade openshift-ansibleUpgrade conmon | Feb 18, 2021 | Oct 1, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 1, 2020 |
| Suse | — | Upgrade ant-manualUpgrade maven-script-antUpgrade plexus-ant-factoryUpgrade ant-xzUpgrade antlr-bootstrapUpgrade ant-junit5Upgrade maven-antrun-pluginUpgrade ant-contribUpgrade ant-jmfUpgrade ant-contrib-javadocUpgrade jetty-antUpgrade ant-antlrUpgrade antlr4-javaUpgrade antlr3-java-javadocUpgrade ant-contrib-manualUpgrade antlr3-toolUpgrade maven-antrun-plugin-javadocUpgrade ant-swingUpgrade ant-jdependUpgrade ant-apache-oroUpgrade antlr3-javaUpgrade ant-apache-bcelUpgrade maven-plugin-tools-antUpgrade jsch-agent-proxy-pageantUpgrade ant-apache-resolverUpgrade ant-commons-loggingUpgrade antlr4-toolUpgrade groovy-antUpgrade antlr-manualUpgrade ant-javamailUpgrade antUpgrade antlr4-maven-pluginUpgrade antlr3-javadocUpgrade antlrUpgrade paranamer-antUpgrade antlr-javaUpgrade ant-testutilUpgrade ant-apache-bsfUpgrade antlr4-javadocUpgrade antlr3-bootstrap-toolUpgrade ant-junitUpgrade ant-commons-netUpgrade ant-apache-log4jUpgrade ant-apache-xalan2Upgrade plexus-ant-factory-javadocUpgrade ant-scriptsUpgrade antlr-develUpgrade ant-jschUpgrade libantlr4-runtime-develUpgrade ant-apache-regexpUpgrade ant-scalaUpgrade ant-javadocUpgrade ant-imageio | Aug 9, 2024 | Oct 1, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 1, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub