CVE-2020-11979: Apache Ant

High severity, CVSS 7.5. EPSS: 8% chance of exploitation in the next 30 days.

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Affected products

  • Apache Ant: version 1.10.8 only
  • Fedoraproject Fedora: version 31 only; version 32 only; version 33 only
  • Gradle Gradle: before 6.8.0 (fixed in 6.8.0)
  • Oracle Agile Engineering Data Management: version 6.2.1.0 only
  • Oracle API Gateway: version 11.1.2.4.0 only
  • Oracle Banking Platform: version 2.4.0 only; version 2.4.1 only; version 2.6.2 only; version 2.7.0 only; version 2.7.1 only; version 2.8.0 only
  • Oracle Banking Treasury Management: version 14.4 only
  • Oracle Communications Unified Inventory Management: version 7.4.0 only; version 7.4.1 only
  • Oracle Data Integrator: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Endeca Information Discovery Studio: version 3.2.0.0 only
  • Oracle Enterprise Repository: version 11.1.1.7.0 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.0.9; version 8.1.0 only; version 8.1.1 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Primavera Gateway: from 16.2.0, up to and including 16.2.11; from 17.12.0, up to and including 17.12.9
  • Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 16.1 only; version 16.2 only; version 18.8 only; version 19.12 only; version 20.12 only
  • Oracle Real-Time Decision Server: version 3.2.0.0 only; version 11.1.1.9.0 only
  • Oracle Retail Advanced Inventory Planning: version 14.1 only
  • Oracle Retail Assortment Planning: version 16.0.3 only
  • Oracle Retail Category Management Planning & Optimization: version 16.0.3 only
  • Oracle Retail Eftlink: version 19.0.1 only; version 20.0.0 only
  • Oracle Retail Financial Integration: version 14.1.3 only; version 15.0.3 only; version 16.0.3 only
  • Oracle Retail Integration Bus: version 15.0.3 only
  • Oracle Retail Item Planning: version 16.0.3 only
  • Oracle Retail Macro Space Optimization: version 16.0.3 only
  • Oracle Retail Merchandise Financial Planning: version 16.0.3 only
  • and 12 more

Published 2020-10-01. Last modified 2026-10-08.