CVE-2020-11979High· 7.5▾ TwilightAs mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
8.0%
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
ant = 1.10.8gradle < 6.8.0fedora = 31fedora = 32fedora = 33agile_engineering_data_management = 6.2.1.0api_gateway = 11.1.2.4.0banking_platform = 2.4.0banking_platform = 2.4.1banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1banking_platform = 2.8.0banking_treasury_management = 14.4communications_unified_inventory_management = 7.4.0communications_unified_inventory_management = 7.4.1data_integrator = 12.2.1.3.0data_integrator = 12.2.1.4.0endeca_information_discovery_studio = 3.2.0.0enterprise_repository = 11.1.1.7.0financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9financial_services_analytical_applications_infrastructure = 8.1.0financial_services_analytical_applications_infrastructure = 8.1.1flexcube_private_banking = 12.0.0flexcube_private_banking = 12.1.0primavera_gateway >= 16.2.0, <= 16.2.11primavera_gateway >= 17.12.0, <= 17.12.9primavera_unifier >= 17.7, <= 17.12primavera_unifier = 16.1primavera_unifier = 16.2primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12real-time_decision_server = 3.2.0.0real-time_decision_server = 11.1.1.9.0retail_advanced_inventory_planning = 14.1retail_assortment_planning = 16.0.3retail_category_management_planning_&_optimization = 16.0.3retail_eftlink = 19.0.1retail_eftlink = 20.0.0retail_financial_integration = 14.1.3retail_financial_integration = 15.0.3retail_financial_integration = 16.0.3retail_integration_bus = 15.0.3retail_item_planning = 16.0.3retail_macro_space_optimization = 16.0.3retail_merchandise_financial_planning = 16.0.3retail_merchandising_system = 14.1.3.2retail_merchandising_system = 16.0.3retail_predictive_application_server = 14.1retail_regular_price_optimization = 16.0.3retail_replenishment_optimization = 16.0.3retail_service_backbone = 14.1.3retail_service_backbone = 15.0.3retail_service_backbone = 16.0.3retail_size_profile_optimization = 16.0.3retail_store_inventory_management = 14.1.3.9retail_store_inventory_management = 15.0.3.0retail_store_inventory_management = 16.0.3.0retail_xstore_point_of_service = 15.0.4retail_xstore_point_of_service = 16.0.6retail_xstore_point_of_service = 17.0.4retail_xstore_point_of_service = 18.0.3retail_xstore_point_of_service = 19.0.2storagetek_acsls = 8.5.1storagetek_tape_analytics = 2.4timesten_in-memory_database < 11.2.2.8.27utilities_framework = 4.3.0.5.0utilities_framework = 4.3.0.6.0utilities_framework = 4.4.0.0.0utilities_framework = 4.4.0.2.0Upgrade past the affected range:
gradle 6.8.0timesten_in-memory_database 11.2.2.8.27Connected by shared product, vendor, weakness, or advisory.
CVE-2021-36374Medium· 5.5When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs
CVE-2021-36373Medium· 5.5When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs
CVE-2021-21290Medium· 6.2Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2026-78254High· 7.4The ftp and scp tasks of Apache Ant can download files from a remote server
CVE-2026-104714High· 8.8Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts
CVE-2026-104713Medium· 6.5Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin