{"id":"CVE-2020-11979","title":"As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them","summary":"As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-379"],"vendor":"apache","product":"ant","affected":["ant = 1.10.8","gradle < 6.8.0","fedora = 31","fedora = 32","fedora = 33","agile_engineering_data_management = 6.2.1.0","api_gateway = 11.1.2.4.0","banking_platform = 2.4.0","banking_platform = 2.4.1","banking_platform = 2.6.2","banking_platform = 2.7.0","banking_platform = 2.7.1","banking_platform = 2.8.0","banking_treasury_management = 14.4","communications_unified_inventory_management = 7.4.0","communications_unified_inventory_management = 7.4.1","data_integrator = 12.2.1.3.0","data_integrator = 12.2.1.4.0","endeca_information_discovery_studio = 3.2.0.0","enterprise_repository = 11.1.1.7.0","financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9","financial_services_analytical_applications_infrastructure = 8.1.0","financial_services_analytical_applications_infrastructure = 8.1.1","flexcube_private_banking = 12.0.0","flexcube_private_banking = 12.1.0","primavera_gateway >= 16.2.0, <= 16.2.11","primavera_gateway >= 17.12.0, <= 17.12.9","primavera_unifier >= 17.7, <= 17.12","primavera_unifier = 16.1","primavera_unifier = 16.2","primavera_unifier = 18.8","primavera_unifier = 19.12","primavera_unifier = 20.12","real-time_decision_server = 3.2.0.0","real-time_decision_server = 11.1.1.9.0","retail_advanced_inventory_planning = 14.1","retail_assortment_planning = 16.0.3","retail_category_management_planning_&_optimization = 16.0.3","retail_eftlink = 19.0.1","retail_eftlink = 20.0.0","retail_financial_integration = 14.1.3","retail_financial_integration = 15.0.3","retail_financial_integration = 16.0.3","retail_integration_bus = 15.0.3","retail_item_planning = 16.0.3","retail_macro_space_optimization = 16.0.3","retail_merchandise_financial_planning = 16.0.3","retail_merchandising_system = 14.1.3.2","retail_merchandising_system = 16.0.3","retail_predictive_application_server = 14.1","retail_regular_price_optimization = 16.0.3","retail_replenishment_optimization = 16.0.3","retail_service_backbone = 14.1.3","retail_service_backbone = 15.0.3","retail_service_backbone = 16.0.3","retail_size_profile_optimization = 16.0.3","retail_store_inventory_management = 14.1.3.9","retail_store_inventory_management = 15.0.3.0","retail_store_inventory_management = 16.0.3.0","retail_xstore_point_of_service = 15.0.4","retail_xstore_point_of_service = 16.0.6","retail_xstore_point_of_service = 17.0.4","retail_xstore_point_of_service = 18.0.3","retail_xstore_point_of_service = 19.0.2","storagetek_acsls = 8.5.1","storagetek_tape_analytics = 2.4","timesten_in-memory_database < 11.2.2.8.27","utilities_framework = 4.3.0.5.0","utilities_framework = 4.3.0.6.0","utilities_framework = 4.4.0.0.0","utilities_framework = 4.4.0.2.0"],"patched":["gradle 6.8.0","timesten_in-memory_database 11.2.2.8.27"],"published":"2020-10-01","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:55.507","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-11979","references":[{"url":"https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/","label":"security@apache.org"},{"url":"https://security.gentoo.org/glsa/202011-18","label":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202011-18","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.08016,"epssPercentile":0.94637,"ingestedAt":"2026-10-08T23:16:47.308Z","slug":"CVE-2020-11979","body":"## Overview\n\nAs mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.\n\n## Affected\n\n- `ant = 1.10.8`\n- `gradle < 6.8.0`\n- `fedora = 31`\n- `fedora = 32`\n- `fedora = 33`\n- `agile_engineering_data_management = 6.2.1.0`\n- `api_gateway = 11.1.2.4.0`\n- `banking_platform = 2.4.0`\n- `banking_platform = 2.4.1`\n- `banking_platform = 2.6.2`\n- `banking_platform = 2.7.0`\n- `banking_platform = 2.7.1`\n- `banking_platform = 2.8.0`\n- `banking_treasury_management = 14.4`\n- `communications_unified_inventory_management = 7.4.0`\n- `communications_unified_inventory_management = 7.4.1`\n- `data_integrator = 12.2.1.3.0`\n- `data_integrator = 12.2.1.4.0`\n- `endeca_information_discovery_studio = 3.2.0.0`\n- `enterprise_repository = 11.1.1.7.0`\n- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9`\n- `financial_services_analytical_applications_infrastructure = 8.1.0`\n- `financial_services_analytical_applications_infrastructure = 8.1.1`\n- `flexcube_private_banking = 12.0.0`\n- `flexcube_private_banking = 12.1.0`\n- `primavera_gateway >= 16.2.0, <= 16.2.11`\n- `primavera_gateway >= 17.12.0, <= 17.12.9`\n- `primavera_unifier >= 17.7, <= 17.12`\n- `primavera_unifier = 16.1`\n- `primavera_unifier = 16.2`\n- `primavera_unifier = 18.8`\n- `primavera_unifier = 19.12`\n- `primavera_unifier = 20.12`\n- `real-time_decision_server = 3.2.0.0`\n- `real-time_decision_server = 11.1.1.9.0`\n- `retail_advanced_inventory_planning = 14.1`\n- `retail_assortment_planning = 16.0.3`\n- `retail_category_management_planning_&_optimization = 16.0.3`\n- `retail_eftlink = 19.0.1`\n- `retail_eftlink = 20.0.0`\n- `retail_financial_integration = 14.1.3`\n- `retail_financial_integration = 15.0.3`\n- `retail_financial_integration = 16.0.3`\n- `retail_integration_bus = 15.0.3`\n- `retail_item_planning = 16.0.3`\n- `retail_macro_space_optimization = 16.0.3`\n- `retail_merchandise_financial_planning = 16.0.3`\n- `retail_merchandising_system = 14.1.3.2`\n- `retail_merchandising_system = 16.0.3`\n- `retail_predictive_application_server = 14.1`\n- `retail_regular_price_optimization = 16.0.3`\n- `retail_replenishment_optimization = 16.0.3`\n- `retail_service_backbone = 14.1.3`\n- `retail_service_backbone = 15.0.3`\n- `retail_service_backbone = 16.0.3`\n- `retail_size_profile_optimization = 16.0.3`\n- `retail_store_inventory_management = 14.1.3.9`\n- `retail_store_inventory_management = 15.0.3.0`\n- `retail_store_inventory_management = 16.0.3.0`\n- `retail_xstore_point_of_service = 15.0.4`\n- `retail_xstore_point_of_service = 16.0.6`\n- `retail_xstore_point_of_service = 17.0.4`\n- `retail_xstore_point_of_service = 18.0.3`\n- `retail_xstore_point_of_service = 19.0.2`\n- `storagetek_acsls = 8.5.1`\n- `storagetek_tape_analytics = 2.4`\n- `timesten_in-memory_database < 11.2.2.8.27`\n- `utilities_framework = 4.3.0.5.0`\n- `utilities_framework = 4.3.0.6.0`\n- `utilities_framework = 4.4.0.0.0`\n- `utilities_framework = 4.4.0.2.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `gradle 6.8.0`\n- `timesten_in-memory_database 11.2.2.8.27`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.6,"exploitation":0,"ransomware":0},"changes":[]}