Lucene search

K
nvd[email protected]NVD:CVE-2020-11979
HistoryOct 01, 2020 - 8:15 p.m.

CVE-2020-11979

2020-10-0120:15:13
CWE-379
web.nvd.nist.gov
1

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.002 Low

EPSS

Percentile

52.0%

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Affected configurations

NVD
Node
apacheantMatch1.10.8
Node
gradlegradleRange<6.8.0
Node
fedoraprojectfedoraMatch31
OR
fedoraprojectfedoraMatch32
OR
fedoraprojectfedoraMatch33
Node
oracleagile_engineering_data_managementMatch6.2.1.0
OR
oracleapi_gatewayMatch11.1.2.4.0
OR
oraclebanking_platformMatch2.4.0
OR
oraclebanking_platformMatch2.4.1
OR
oraclebanking_platformMatch2.6.2
OR
oraclebanking_platformMatch2.7.0
OR
oraclebanking_platformMatch2.7.1
OR
oraclebanking_platformMatch2.8.0
OR
oraclebanking_treasury_managementMatch14.4
OR
oraclecommunications_unified_inventory_managementMatch7.4.0
OR
oraclecommunications_unified_inventory_managementMatch7.4.1
OR
oracledata_integratorMatch12.2.1.3.0
OR
oracledata_integratorMatch12.2.1.4.0
OR
oracleendeca_information_discovery_studioMatch3.2.0.0
OR
oracleenterprise_repositoryMatch11.1.1.7.0
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.68.0.9
OR
oraclefinancial_services_analytical_applications_infrastructureMatch8.1.0
OR
oraclefinancial_services_analytical_applications_infrastructureMatch8.1.1
OR
oracleflexcube_private_bankingMatch12.0.0
OR
oracleflexcube_private_bankingMatch12.1.0
OR
oracleprimavera_gatewayRange16.2.016.2.11
OR
oracleprimavera_gatewayRange17.12.017.12.9
OR
oracleprimavera_unifierRange17.717.12
OR
oracleprimavera_unifierMatch16.1
OR
oracleprimavera_unifierMatch16.2
OR
oracleprimavera_unifierMatch18.8
OR
oracleprimavera_unifierMatch19.12
OR
oracleprimavera_unifierMatch20.12
OR
oraclereal-time_decision_serverMatch3.2.0.0
OR
oraclereal-time_decision_serverMatch11.1.1.9.0
OR
oracleretail_advanced_inventory_planningMatch14.1
OR
oracleretail_assortment_planningMatch16.0.3
OR
oracleretail_category_management_planning_\&_optimizationMatch16.0.3
OR
oracleretail_eftlinkMatch19.0.1
OR
oracleretail_eftlinkMatch20.0.0
OR
oracleretail_financial_integrationMatch14.1.3
OR
oracleretail_financial_integrationMatch15.0.3
OR
oracleretail_financial_integrationMatch16.0.3
OR
oracleretail_integration_busMatch15.0.3
OR
oracleretail_item_planningMatch16.0.3
OR
oracleretail_macro_space_optimizationMatch16.0.3
OR
oracleretail_merchandise_financial_planningMatch16.0.3
OR
oracleretail_merchandising_systemMatch14.1.3.2
OR
oracleretail_merchandising_systemMatch16.0.3
OR
oracleretail_predictive_application_serverMatch14.1
OR
oracleretail_regular_price_optimizationMatch16.0.3
OR
oracleretail_replenishment_optimizationMatch16.0.3
OR
oracleretail_service_backboneMatch14.1.3
OR
oracleretail_service_backboneMatch15.0.3
OR
oracleretail_service_backboneMatch16.0.3
OR
oracleretail_size_profile_optimizationMatch16.0.3
OR
oracleretail_store_inventory_managementMatch14.1.3.9
OR
oracleretail_store_inventory_managementMatch15.0.3.0
OR
oracleretail_store_inventory_managementMatch16.0.3.0
OR
oracleretail_xstore_point_of_serviceMatch15.0.4
OR
oracleretail_xstore_point_of_serviceMatch16.0.6
OR
oracleretail_xstore_point_of_serviceMatch17.0.4
OR
oracleretail_xstore_point_of_serviceMatch18.0.3
OR
oracleretail_xstore_point_of_serviceMatch19.0.2
OR
oraclestoragetek_acslsMatch8.5.1
OR
oraclestoragetek_tape_analyticsMatch2.4
OR
oracletimesten_in-memory_databaseRange<11.2.2.8.27
OR
oracleutilities_frameworkMatch4.3.0.5.0
OR
oracleutilities_frameworkMatch4.3.0.6.0
OR
oracleutilities_frameworkMatch4.4.0.0.0
OR
oracleutilities_frameworkMatch4.4.0.2.0

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.002 Low

EPSS

Percentile

52.0%