Permissions, Privileges, and Access Controls in Apache Ant - CVE-2020-11979

 

Permissions, Privileges, and Access Controls in Apache Ant - CVE-2020-11979

Published: May 14, 2020 / Updated: October 8, 2020


Vulnerability identifier: #VU47428
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11979
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect patch for vulnerability #VU27924 (CVE-2020-1945). Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.


Affected software

Apache Ant
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Fedora
runc (Red Hat package)
cri-o (Red Hat package)
apache-ant (Alpine package)
jenkins (Red Hat package)
conmon (Red Hat package)
python-rsa (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
ant-swing
ant-scripts
ant
ant-jmf
ant-apache-log4j
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-oro
ant-jdepend
ant-antlr
ant-apache-bcel
ant-apache-bsf
ant-javamail
ant-junit
ant-manual
IBM Cloud Pak System
Oracle Utilities Network Management System
Oracle Banking Platform
Oracle Utilities Framework
Oracle Agile Engineering Data Management
Oracle Financial Services Analytical Applications Infrastructure
webMethods BPM
Oracle FLEXCUBE Private Banking
Oracle Retail Service Backbone
Oracle Retail Store Inventory Management
Oracle Retail Xstore Point of Service
Oracle StorageTek Tape Analytics (STA)
Oracle Communications Unified Inventory Management
Oracle StorageTek ACSLS
Oracle Banking Treasury Management
Log Analysis
IBM Cloud Pak for Data System
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Oracle Endeca Information Discovery Studio
Oracle Enterprise Repository
Red Hat OpenShift Container Platform
Primavera Unifier
SecureTransport
Oracle API Gateway
Oracle TimesTen In-Memory Database
Oracle Retail Advanced Inventory Planning
Oracle Retail Financial Integration
Oracle Retail Merchandising System
Oracle Retail Merchandise Financial Planning
Oracle Retail Regular Price Optimization
Oracle Retail Replenishment Optimization
Oracle Retail Assortment Planning
Oracle Retail Category Management Planning & Optimization
Oracle Retail Size Profile Optimization
Oracle Retail Item Planning
Oracle Retail Macro Space Optimization
Oracle Retail EFTLink
Oracle Retail Predictive Application Server
Primavera Gateway
Oracle Retail Integration Bus

How to mitigate CVE-2020-11979

Install updates from vendor's website.

Apache Ant - update to 1.10.9
runc (Red Hat package) - addressed in versions 1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8
cri-o (Red Hat package) - update to 1.19.1-7.rhaos4.6.git6377f68.el7
apache-ant (Alpine package) - update to 1.10.9-r0
jenkins (Red Hat package) - addressed in versions 2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8
conmon (Red Hat package) - addressed in versions 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8
IBM Cloud Pak System - update to 2.3.3.6
python-rsa (Red Hat package) - update to 4.7-1.el8
openshift (Red Hat package) - addressed in versions 4.5.0-202102050524.p0.git.0.9229406.el7, 4.5.0-202102050524.p0.git.0.9229406.el8, 4.6.0-202102050212.p0.git.94265.716fcf8.el7, 4.6.0-202102050212.p0.git.94265.716fcf8.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8
openshift-ansible (Red Hat package) - addressed in versions 4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7
openshift-clients (Red Hat package) - addressed in versions 4.5.0-202102051529.p0.git.3612.61b096a.el7, 4.5.0-202102051529.p0.git.3612.61b096a.el8, 4.6.0-202102050644.p0.git.3831.1c61c6b.el7, 4.6.0-202102050644.p0.git.3831.1c61c6b.el8
Red Hat OpenShift Container Platform - addressed in versions 4.5.33, 4.6.17
openshift-kuryr (Red Hat package) - update to 4.6.0-202102031810.p0.git.2225.a3ab872.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.6.0-202102031810.p0.git.15.dcab90a.el8
jenkins-2-plugins (Red Hat package) - update to 4.6.1612257979-1.el8
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Oracle TimesTen In-Memory Database - update to 11.2.2.8.27
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-swing - update to 1.9.4-3.12.1
ant-scripts - update to 1.9.4-3.12.1
ant - update to 1.9.4-3.12.1
ant-jmf - update to 1.9.4-3.12.1
ant-apache-log4j - update to 1.9.4-3.12.3
ant-javadoc - update to 1.9.4-3.12.3
ant-commons-logging - update to 1.9.4-3.12.3
ant-apache-resolver - update to 1.9.4-3.12.3
ant-apache-regexp - update to 1.9.4-3.12.3
ant-apache-oro - update to 1.9.4-3.12.3
ant-jdepend - update to 1.9.4-3.12.3
ant-antlr - update to 1.9.4-3.12.3
ant-apache-bcel - update to 1.9.4-3.12.3
ant-apache-bsf - update to 1.9.4-3.12.3
ant-javamail - update to 1.9.4-3.12.3
ant-junit - update to 1.9.4-3.12.3
ant-manual - update to 1.9.4-3.12.3
ant - addressed in versions 1.10.9-1.fc31, 1.10.9-1.fc32, 1.10.9-1.fc33
IBM Cloud Pak for Data System - update to 2.0.2.1
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3

External References

Related Security Bulletins