---
id: CVE-2020-11979
title: >-
  As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of
  temporary files it created so that only the current user was allowed to access
  them
summary: >-
  As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of
  temporary files it created so that only the current user was allowed to access
  them. Unfortunately the fixcrlf task deleted the temporary file and created a
  new…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-379
vendor: apache
product: ant
affected:
  - ant = 1.10.8
  - gradle < 6.8.0
  - fedora = 31
  - fedora = 32
  - fedora = 33
  - agile_engineering_data_management = 6.2.1.0
  - api_gateway = 11.1.2.4.0
  - banking_platform = 2.4.0
  - banking_platform = 2.4.1
  - banking_platform = 2.6.2
  - banking_platform = 2.7.0
  - banking_platform = 2.7.1
  - banking_platform = 2.8.0
  - banking_treasury_management = 14.4
  - communications_unified_inventory_management = 7.4.0
  - communications_unified_inventory_management = 7.4.1
  - data_integrator = 12.2.1.3.0
  - data_integrator = 12.2.1.4.0
  - endeca_information_discovery_studio = 3.2.0.0
  - enterprise_repository = 11.1.1.7.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9'
  - financial_services_analytical_applications_infrastructure = 8.1.0
  - financial_services_analytical_applications_infrastructure = 8.1.1
  - flexcube_private_banking = 12.0.0
  - flexcube_private_banking = 12.1.0
  - 'primavera_gateway >= 16.2.0, <= 16.2.11'
  - 'primavera_gateway >= 17.12.0, <= 17.12.9'
  - 'primavera_unifier >= 17.7, <= 17.12'
  - primavera_unifier = 16.1
  - primavera_unifier = 16.2
  - primavera_unifier = 18.8
  - primavera_unifier = 19.12
  - primavera_unifier = 20.12
  - real-time_decision_server = 3.2.0.0
  - real-time_decision_server = 11.1.1.9.0
  - retail_advanced_inventory_planning = 14.1
  - retail_assortment_planning = 16.0.3
  - retail_category_management_planning_&_optimization = 16.0.3
  - retail_eftlink = 19.0.1
  - retail_eftlink = 20.0.0
  - retail_financial_integration = 14.1.3
  - retail_financial_integration = 15.0.3
  - retail_financial_integration = 16.0.3
  - retail_integration_bus = 15.0.3
  - retail_item_planning = 16.0.3
  - retail_macro_space_optimization = 16.0.3
  - retail_merchandise_financial_planning = 16.0.3
  - retail_merchandising_system = 14.1.3.2
  - retail_merchandising_system = 16.0.3
  - retail_predictive_application_server = 14.1
  - retail_regular_price_optimization = 16.0.3
  - retail_replenishment_optimization = 16.0.3
  - retail_service_backbone = 14.1.3
  - retail_service_backbone = 15.0.3
  - retail_service_backbone = 16.0.3
  - retail_size_profile_optimization = 16.0.3
  - retail_store_inventory_management = 14.1.3.9
  - retail_store_inventory_management = 15.0.3.0
  - retail_store_inventory_management = 16.0.3.0
  - retail_xstore_point_of_service = 15.0.4
  - retail_xstore_point_of_service = 16.0.6
  - retail_xstore_point_of_service = 17.0.4
  - retail_xstore_point_of_service = 18.0.3
  - retail_xstore_point_of_service = 19.0.2
  - storagetek_acsls = 8.5.1
  - storagetek_tape_analytics = 2.4
  - timesten_in-memory_database < 11.2.2.8.27
  - utilities_framework = 4.3.0.5.0
  - utilities_framework = 4.3.0.6.0
  - utilities_framework = 4.4.0.0.0
  - utilities_framework = 4.4.0.2.0
patched:
  - gradle 6.8.0
  - timesten_in-memory_database 11.2.2.8.27
published: '2020-10-01'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:55.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-11979'
references:
  - url: 'https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/
    label: security@apache.org
  - url: 'https://security.gentoo.org/glsa/202011-18'
    label: security@apache.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security@apache.org
  - url: 'https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202011-18'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.08016
epssPercentile: 0.94637
ingestedAt: '2026-10-08T23:16:47.308Z'
---

## Overview

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

## Affected

- `ant = 1.10.8`
- `gradle < 6.8.0`
- `fedora = 31`
- `fedora = 32`
- `fedora = 33`
- `agile_engineering_data_management = 6.2.1.0`
- `api_gateway = 11.1.2.4.0`
- `banking_platform = 2.4.0`
- `banking_platform = 2.4.1`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.8.0`
- `banking_treasury_management = 14.4`
- `communications_unified_inventory_management = 7.4.0`
- `communications_unified_inventory_management = 7.4.1`
- `data_integrator = 12.2.1.3.0`
- `data_integrator = 12.2.1.4.0`
- `endeca_information_discovery_studio = 3.2.0.0`
- `enterprise_repository = 11.1.1.7.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9`
- `financial_services_analytical_applications_infrastructure = 8.1.0`
- `financial_services_analytical_applications_infrastructure = 8.1.1`
- `flexcube_private_banking = 12.0.0`
- `flexcube_private_banking = 12.1.0`
- `primavera_gateway >= 16.2.0, <= 16.2.11`
- `primavera_gateway >= 17.12.0, <= 17.12.9`
- `primavera_unifier >= 17.7, <= 17.12`
- `primavera_unifier = 16.1`
- `primavera_unifier = 16.2`
- `primavera_unifier = 18.8`
- `primavera_unifier = 19.12`
- `primavera_unifier = 20.12`
- `real-time_decision_server = 3.2.0.0`
- `real-time_decision_server = 11.1.1.9.0`
- `retail_advanced_inventory_planning = 14.1`
- `retail_assortment_planning = 16.0.3`
- `retail_category_management_planning_&_optimization = 16.0.3`
- `retail_eftlink = 19.0.1`
- `retail_eftlink = 20.0.0`
- `retail_financial_integration = 14.1.3`
- `retail_financial_integration = 15.0.3`
- `retail_financial_integration = 16.0.3`
- `retail_integration_bus = 15.0.3`
- `retail_item_planning = 16.0.3`
- `retail_macro_space_optimization = 16.0.3`
- `retail_merchandise_financial_planning = 16.0.3`
- `retail_merchandising_system = 14.1.3.2`
- `retail_merchandising_system = 16.0.3`
- `retail_predictive_application_server = 14.1`
- `retail_regular_price_optimization = 16.0.3`
- `retail_replenishment_optimization = 16.0.3`
- `retail_service_backbone = 14.1.3`
- `retail_service_backbone = 15.0.3`
- `retail_service_backbone = 16.0.3`
- `retail_size_profile_optimization = 16.0.3`
- `retail_store_inventory_management = 14.1.3.9`
- `retail_store_inventory_management = 15.0.3.0`
- `retail_store_inventory_management = 16.0.3.0`
- `retail_xstore_point_of_service = 15.0.4`
- `retail_xstore_point_of_service = 16.0.6`
- `retail_xstore_point_of_service = 17.0.4`
- `retail_xstore_point_of_service = 18.0.3`
- `retail_xstore_point_of_service = 19.0.2`
- `storagetek_acsls = 8.5.1`
- `storagetek_tape_analytics = 2.4`
- `timesten_in-memory_database < 11.2.2.8.27`
- `utilities_framework = 4.3.0.5.0`
- `utilities_framework = 4.3.0.6.0`
- `utilities_framework = 4.4.0.0.0`
- `utilities_framework = 4.4.0.2.0`

## Remediation

Upgrade past the affected range:

- `gradle 6.8.0`
- `timesten_in-memory_database 11.2.2.8.27`
