Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27516
HistoryOct 04, 2020 - 4:38 a.m.

Authorization Bypass

2020-10-0404:38:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.002 Low

EPSS

Percentile

52.0%

apache-ant is vulnerable to authorization bypass. The vulnerabiltiy exists through the mitigation for CVE-2020-1945 has changed the permissions of temporary files it created so that only the current user was allowed to access them, while the fixcrlf task deleted the temporary file and creates a new one without said protection, allowing the injection of modified source files into the build process.

References