/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2020-11979

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2020-11979

Severity

7.5

High

CVSS V3

Description

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

References

Affected packages


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing