Versio.io

CVE-2020-1945

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 14-05-2020 06:15
Last modified: - 04-04-2022 03:31
Total changes: - 12

Description

Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
High
Attack complexity
Local
Attack vector
None
Availability
High
Confidentiality
High
Integrity
Low
Privileges required
Unchanged
Scope
None
User interaction
6.3
Base score
1.0
5.2
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=apache AND product=ant AND versionEndIncluding=1.9.14 AND versionStartIncluding=1.1
vendor=apache AND product=ant AND versionEndIncluding=1.10.7 AND versionStartIncluding=1.10.0
OR
vendor=canonical AND product=ubuntu_linux AND version=19.10
OR
vendor=fedoraproject AND product=fedora AND version=31
vendor=fedoraproject AND product=fedora AND version=32
OR
vendor=opensuse AND product=leap AND version=15.2
OR
vendor=oracle AND product=agile_engineering_data_management AND version=6.2.1.0
vendor=oracle AND product=banking_enterprise_collections AND versionEndIncluding=2.9.0 AND versionStartIncluding=2.7.0
vendor=oracle AND product=banking_liquidity_management AND versionEndIncluding=14.4.0 AND versionStartIncluding=14.0.0
vendor=oracle AND product=banking_platform AND versionEndIncluding=2.9.0 AND versionStartIncluding=2.4.0
vendor=oracle AND product=business_process_management_suite AND version=12.2.1.3.0
vendor=oracle AND product=business_process_management_suite AND version=12.2.1.4.0
vendor=oracle AND product=category_management_planning_\&_optimization AND version=15.0.3
vendor=oracle AND product=communications_asap AND version=7.3
vendor=oracle AND product=communications_diameter_signaling_router AND versionEndIncluding=8.2.2 AND versionStartIncluding=8.0.0
vendor=oracle AND product=communications_metasolv_solution AND version=6.3.0
vendor=oracle AND product=communications_order_and_service_management AND version=7.3
vendor=oracle AND product=communications_order_and_service_management AND version=7.4
vendor=oracle AND product=data_integrator AND version=12.2.1.3.0
vendor=oracle AND product=data_integrator AND version=12.2.1.4.0
vendor=oracle AND product=endeca_information_discovery_studio AND version=3.2.0
vendor=oracle AND product=enterprise_manager_ops_center AND version=12.4.0.0
vendor=oracle AND product=enterprise_repository AND version=11.1.1.7.0
vendor=oracle AND product=financial_services_analytical_applications_infrastructure AND versionEndIncluding=8.1.0 AND versionStartIncluding=8.0.6
vendor=oracle AND product=flexcube_investor_servicing AND version=12.1.0
vendor=oracle AND product=flexcube_investor_servicing AND version=12.3.0
vendor=oracle AND product=flexcube_investor_servicing AND version=12.4.0
vendor=oracle AND product=flexcube_investor_servicing AND version=14.0.0
vendor=oracle AND product=flexcube_investor_servicing AND version=14.1.0
vendor=oracle AND product=flexcube_private_banking AND version=12.0.0
vendor=oracle AND product=flexcube_private_banking AND version=12.1.0
vendor=oracle AND product=health_sciences_information_manager AND versionEndIncluding=3.0.2 AND versionStartIncluding=3.0
vendor=oracle AND product=primavera_gateway AND versionEndIncluding=16.2.11 AND versionStartIncluding=16.2.0
vendor=oracle AND product=primavera_gateway AND versionEndIncluding=17.12.7 AND versionStartIncluding=17.12.0
vendor=oracle AND product=primavera_unifier AND version=16.1
vendor=oracle AND product=primavera_unifier AND version=16.2
vendor=oracle AND product=primavera_unifier AND versionEndIncluding=17.12 AND versionStartIncluding=17.7
vendor=oracle AND product=primavera_unifier AND version=18.8
vendor=oracle AND product=primavera_unifier AND version=19.12
vendor=oracle AND product=rapid_planning AND version=12.1
vendor=oracle AND product=rapid_planning AND version=12.2
vendor=oracle AND product=real-time_decision_server AND version=3.2.1.0
vendor=oracle AND product=retail_advanced_inventory_planning AND version=14.1
vendor=oracle AND product=retail_advanced_inventory_planning AND version=15.0
vendor=oracle AND product=retail_advanced_inventory_planning AND version=16.0
vendor=oracle AND product=retail_assortment_planning AND version=15.0.3
vendor=oracle AND product=retail_assortment_planning AND version=16.0.3
vendor=oracle AND product=retail_back_office AND version=14.0
vendor=oracle AND product=retail_back_office AND version=14.1
vendor=oracle AND product=retail_bulk_data_integration AND version=15.0
vendor=oracle AND product=retail_bulk_data_integration AND version=16.0
vendor=oracle AND product=retail_bulk_data_integration AND version=16.0.3.0
vendor=oracle AND product=retail_bulk_data_integration AND version=19.0.1
vendor=oracle AND product=retail_central_office AND version=14.0
vendor=oracle AND product=retail_central_office AND version=14.1
vendor=oracle AND product=retail_data_extractor_for_merchandising AND version=1.9
vendor=oracle AND product=retail_data_extractor_for_merchandising AND version=1.10
vendor=oracle AND product=retail_extract_transform_and_load AND version=13.2.5
vendor=oracle AND product=retail_extract_transform_and_load AND version=13.2.8
vendor=oracle AND product=retail_financial_integration AND version=14.1.3.2
vendor=oracle AND product=retail_financial_integration AND version=15.0
vendor=oracle AND product=retail_financial_integration AND version=15.0.4.0
vendor=oracle AND product=retail_financial_integration AND version=16.0
vendor=oracle AND product=retail_financial_integration AND version=16.0.3.0
vendor=oracle AND product=retail_integration_bus AND version=14.1
vendor=oracle AND product=retail_integration_bus AND version=14.1.3.2
vendor=oracle AND product=retail_integration_bus AND version=15.0
vendor=oracle AND product=retail_integration_bus AND version=15.0.4.0
vendor=oracle AND product=retail_integration_bus AND version=16.0
vendor=oracle AND product=retail_integration_bus AND version=16.0.3.0
vendor=oracle AND product=retail_integration_bus AND version=19.0.1.0
vendor=oracle AND product=retail_item_planning AND version=15.0.3
vendor=oracle AND product=retail_macro_space_optimization AND version=15.0.3
vendor=oracle AND product=retail_merchandise_financial_planning AND version=15.0.3
vendor=oracle AND product=retail_merchandising_system AND version=19.0.1
vendor=oracle AND product=retail_point-of-service AND version=14.0
vendor=oracle AND product=retail_point-of-service AND version=14.1
vendor=oracle AND product=retail_point-of-service AND version=15.0
vendor=oracle AND product=retail_point-of-service AND version=16.0
vendor=oracle AND product=retail_predictive_application_server AND version=14.0.3
vendor=oracle AND product=retail_predictive_application_server AND version=14.1.3
vendor=oracle AND product=retail_predictive_application_server AND version=15.0.3
vendor=oracle AND product=retail_predictive_application_server AND version=16.0.3
vendor=oracle AND product=retail_predictive_application_server AND version=16.0.3.0
vendor=oracle AND product=retail_regular_price_optimization AND version=15.0.3
vendor=oracle AND product=retail_regular_price_optimization AND version=16.0.3
vendor=oracle AND product=retail_replenishment_optimization AND version=15.0.3
vendor=oracle AND product=retail_returns_management AND version=14.0
vendor=oracle AND product=retail_returns_management AND version=14.1
vendor=oracle AND product=retail_service_backbone AND version=14.1.3.2
vendor=oracle AND product=retail_service_backbone AND version=15.0
vendor=oracle AND product=retail_service_backbone AND version=15.0.4.0
vendor=oracle AND product=retail_service_backbone AND version=16.0
vendor=oracle AND product=retail_service_backbone AND version=16.0.3.0
vendor=oracle AND product=retail_service_backbone AND version=19.0.1.0
vendor=oracle AND product=retail_size_profile_optimization AND version=15.0.3
vendor=oracle AND product=retail_size_profile_optimization AND version=16.0.3
vendor=oracle AND product=retail_store_inventory_management AND version=14.0.4
vendor=oracle AND product=retail_store_inventory_management AND version=14.1
vendor=oracle AND product=retail_store_inventory_management AND version=14.1.3
vendor=oracle AND product=retail_store_inventory_management AND version=15.0
vendor=oracle AND product=retail_store_inventory_management AND version=15.0.3
vendor=oracle AND product=retail_store_inventory_management AND version=16.0
vendor=oracle AND product=retail_store_inventory_management AND version=16.0.3
vendor=oracle AND product=retail_xstore_point_of_service AND version=15.0.4
vendor=oracle AND product=retail_xstore_point_of_service AND version=16.0.6
vendor=oracle AND product=retail_xstore_point_of_service AND version=17.0.4
vendor=oracle AND product=retail_xstore_point_of_service AND version=18.0.3
vendor=oracle AND product=retail_xstore_point_of_service AND version=19.0.2
vendor=oracle AND product=timesten_in-memory_database AND versionEndExcluding=11.2.2.8.27
vendor=oracle AND product=timesten_in-memory_database AND version=11.2.2.8.49
vendor=oracle AND product=utilities_framework AND version=2.2.0.0.0
vendor=oracle AND product=utilities_framework AND version=4.2.0.2.0
vendor=oracle AND product=utilities_framework AND version=4.2.0.3.0
vendor=oracle AND product=utilities_framework AND versionEndIncluding=4.3.0.6.0 AND versionStartIncluding=4.3.0.1.0
vendor=oracle AND product=utilities_framework AND version=4.4.0.0.0
vendor=oracle AND product=utilities_framework AND version=4.4.0.2.0
 

Reference

 


Keywords

NVD

 

CVE-2020-1945

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.