ant: insecure temporary file
Published Oct 1, 2020
7.5
HIGHCVSS 3.1
EPSS 8.02%
Description
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Affected products
- Vendor n/a Product Apache Ant Defaultn/a
- Version Apache Ant 1.10.8StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache Ant | n/a |
|
Configuration 3
- 31
- 32
- 33
Configuration 4
- 6.2.1.0
- 11.1.2.4.0
- 2.4.0
- 2.4.1
- 2.6.2
- 2.7.0
- 2.7.1
- 2.8.0
- 14.4
- 7.4.0
- 7.4.1
- 12.2.1.3.0
- 12.2.1.4.0
- 3.2.0.0
- 11.1.1.7.0
- ≥ 8.0.6 · ≤ 8.0.9
- 8.1.0
- 8.1.1
- 12.0.0
- 12.1.0
- ≥ 16.2.0 · ≤ 16.2.11
- ≥ 17.12.0 · ≤ 17.12.9
- ≥ 17.7 · ≤ 17.12
- 16.1
- 16.2
- 18.8
- 19.12
- 20.12
- 3.2.0.0
- 11.1.1.9.0
- 14.1
- 16.0.3
- 16.0.3
- 19.0.1
- 20.0.0
- 14.1.3
- 15.0.3
- 16.0.3
- 15.0.3
- 16.0.3
- 16.0.3
- 16.0.3
- 14.1.3.2
- 16.0.3
- 14.1
- 16.0.3
- 16.0.3
- 14.1.3
- 15.0.3
- 16.0.3
- 16.0.3
- 14.1.3.9
- 15.0.3.0
- 16.0.3.0
- 15.0.4
- 16.0.6
- 17.0.4
- 18.0.3
- 19.0.2
- 8.5.1
- 2.4
- < 11.2.2.8.27
- 4.3.0.5.0
- 4.3.0.6.0
- 4.4.0.0.0
- 4.4.0.2.0
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.263.3.1612433584-1.el7
Fixed · RHSA-2021:0637
Red Hat OpenShift Container Platform 4.5
conmon-2:2.0.21-1.rhaos4.5.el7
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.5
jenkins-0:2.263.3.1612434332-1.el7
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.5
machine-config-daemon-0:4.5.0-202102050524.p0.git.2594.ff3b8c0.el8
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.5
openshift-0:4.5.0-202102050524.p0.git.0.9229406.el7
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.5
openshift-ansible-0:4.5.0-202102031005.p0.git.0.c6839a2.el7
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.5
openshift-clients-0:4.5.0-202102051529.p0.git.3612.61b096a.el7
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.5
runc-0:1.0.0-72.rhaos4.5.giteadfc6b.el8
Fixed · RHSA-2021:0429
Red Hat OpenShift Container Platform 4.6
jenkins-0:2.263.3.1612434510-1.el8
Fixed · RHSA-2021:0423
Red Hat BPM Suite 6
ant
Out of support scope
Red Hat Decision Manager 7
ant
Will not fix
Red Hat Enterprise Linux 5
ant
Out of support scope
Red Hat Enterprise Linux 6
ant
Out of support scope
Red Hat Enterprise Linux 7
ant
Out of support scope
Red Hat Enterprise Linux 8
ant
Not affected
Red Hat Enterprise Linux 8
ant:1.10/ant
Not affected
Red Hat JBoss BRMS 5
ant
Out of support scope
Red Hat JBoss Data Virtualization 6
ant
Out of support scope
Red Hat JBoss Enterprise Application Platform 5
ant
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
ant
Out of support scope
Red Hat JBoss Fuse Service Works 6
ant
Out of support scope
Red Hat JBoss Operations Network 3
ant
Out of support scope
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Not affected
Red Hat OpenShift Container Platform 4
jenkins-2-plugins
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hive
Will not fix
Red Hat Process Automation 7
ant
Will not fix
Red Hat Single Sign-On 7
rh-sso7-keycloak
Not affected
streams for Apache Kafka
ant
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.263.3.1612433584-1.el7 | Fixed | RHSA-2021:0637 |
| Red Hat OpenShift Container Platform 4.5 | conmon-2:2.0.21-1.rhaos4.5.el7 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.5 | jenkins-0:2.263.3.1612434332-1.el7 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.5 | machine-config-daemon-0:4.5.0-202102050524.p0.git.2594.ff3b8c0.el8 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.5 | openshift-0:4.5.0-202102050524.p0.git.0.9229406.el7 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.5 | openshift-ansible-0:4.5.0-202102031005.p0.git.0.c6839a2.el7 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.5 | openshift-clients-0:4.5.0-202102051529.p0.git.3612.61b096a.el7 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.5 | runc-0:1.0.0-72.rhaos4.5.giteadfc6b.el8 | Fixed | RHSA-2021:0429 |
| Red Hat OpenShift Container Platform 4.6 | jenkins-0:2.263.3.1612434510-1.el8 | Fixed | RHSA-2021:0423 |
| Red Hat BPM Suite 6 | ant | Out of support scope | n/a |
| Red Hat Decision Manager 7 | ant | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | ant | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | ant | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ant | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | ant | Not affected | n/a |
| Red Hat Enterprise Linux 8 | ant:1.10/ant | Not affected | n/a |
| Red Hat JBoss BRMS 5 | ant | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | ant | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | ant | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | ant | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | ant | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | ant | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hive | Will not fix | n/a |
| Red Hat Process Automation 7 | ant | Will not fix | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Not affected | n/a |
| streams for Apache Kafka | ant | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
ant as shipped in Red Hat Enterprise Linux 8 is not affected by this flaw because this flaw is caused by the patch for CVE-2020-1945, however, it was never applied to ant as shipped in Red Hat Enterprise Linux 8, because the decision was made by Engineering to WONTFIX that flaw. In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of ant package. Since the release of OCP 4.6, the Metering product has been deprecated [1], hence the affected components are marked as wontfix. This may be fixed in the future. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.02% (0.08016) | 94.60th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.14% (0.08137) | 94.10th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.61% (0.00610) | 68.94th | v4 (v2025.03.14) |
| Nov 18, 2025 | 6.83% (0.06825) | 90.42th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.80% (0.00802) | 72.42th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.20% (0.00202) | 59.13th | v3 (v2023.03.01) |
| May 15, 2024 | 0.15% (0.00154) | 51.53th | v3 (v2023.03.01) |
| Jan 3, 2024 | 0.18% (0.00183) | 55.63th | v3 (v2023.03.01) |
| Nov 18, 2023 | 0.16% (0.00159) | 52.31th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.18% (0.00185) | 55.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00177) | 52.99th | v3 (v2023.03.01) |
| Mar 6, 2023 | 5.24% (0.05242) | 89.75th | v2 (v2022.01.01) |
| Apr 1, 2022 | 5.24% (0.05242) | 88.72th | v2 (v2022.01.01) |
| Mar 31, 2022 | 34.28% (0.34284) | 96.74th | v2 (v2022.01.01) |
| Jan 6, 2022 | 34.02% (0.34016) | 97.70th | v1 |
| Jan 5, 2022 | 10.31% (0.10306) | 95.22th | v1 |
| Jul 21, 2021 | 9.79% (0.09785) | 0.00th | v1 |
| Jun 15, 2021 | 8.73% (0.08728) | 0.00th | v5 (v2026.06.15) |
| Apr 14, 2021 | 7.65% (0.07646) | 0.00th | v1 |
References (35)
- https://access.redhat.com/security/cve/CVE-2020-11979 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1903702 Issue Tracking
- https://github.com/advisories/GHSA-f62v-xpxf-3v68 Advisory
- https://github.com/apache/ant/commit/87ac51d3c22bcf7cfd0dc07cb0bd04a496e0d428
- https://github.com/gradle/gradle/security/advisories/GHSA-j45w-qrgf-25vm x_refsource_MISCThird Party Advisory
- https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/raaeddc41da8f3afb1cb224876084a45f68e437a0afd9889a707e4b0c@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a%40%3Cdev.creadur.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rbfe9ba28b74f39f46ec1bbbac3bef313f35017cf3aac13841a84483a@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E x_refsource_MISCMailing ListVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AALW42FWNQ35F7KB3JVRC6NBVV7AAYYI
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DYBRN5C2RW7JRY75IB7Q7ZVKZCHWAQWS
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3NRQQ7ECII4ZNGW7GBC225LVYMPQEKB
- https://nvd.nist.gov/vuln/detail/CVE-2020-11979
- https://security.gentoo.org/glsa/202011-18 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-11979
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.