As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.10.8"
},
{
"introduced": "0"
},
{
"last_affected": "31"
},
{
"introduced": "0"
},
{
"last_affected": "16.1"
},
{
"introduced": "0"
},
{
"last_affected": "16.2"
},
{
"introduced": "0"
},
{
"last_affected": "14.1"
},
{
"introduced": "0"
},
{
"last_affected": "14.1"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "6.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "7.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "8.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "8.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.4"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.2.1.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.2.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.2.1.4.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.2.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.1.7.0"
}
]
},
{
"events": [
{
"introduced": "8.0.6"
},
{
"last_affected": "8.0.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.1.0"
}
]
},
{
"events": [
{
"introduced": "16.2.0"
},
{
"last_affected": "16.2.11"
}
]
},
{
"events": [
{
"introduced": "17.12.0"
},
{
"last_affected": "17.12.9"
}
]
},
{
"events": [
{
"introduced": "17.7"
},
{
"last_affected": "17.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.2.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.1.1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.1.3.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.3.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "17.0.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.0.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.0.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.5.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "11.2.2.8.27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.3.0.5.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.3.0.6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.4.0.0.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.4.0.2.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11979.json"