Permissions, Privileges, and Access Controls in Apache Ant - CVE-2020-11979
Published: May 14, 2020 / Updated: October 8, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect patch for vulnerability #VU27924 (CVE-2020-1945). Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Affected software
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Fedora
runc (Red Hat package)
cri-o (Red Hat package)
apache-ant (Alpine package)
jenkins (Red Hat package)
conmon (Red Hat package)
python-rsa (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
ant-swing
ant-scripts
ant
ant-jmf
ant-apache-log4j
ant-javadoc
ant-commons-logging
ant-apache-resolver
ant-apache-regexp
ant-apache-oro
ant-jdepend
ant-antlr
ant-apache-bcel
ant-apache-bsf
ant-javamail
ant-junit
ant-manual
IBM Cloud Pak System
Oracle Utilities Network Management System
Oracle Banking Platform
Oracle Utilities Framework
Oracle Agile Engineering Data Management
Oracle Financial Services Analytical Applications Infrastructure
webMethods BPM
Oracle FLEXCUBE Private Banking
Oracle Retail Service Backbone
Oracle Retail Store Inventory Management
Oracle Retail Xstore Point of Service
Oracle StorageTek Tape Analytics (STA)
Oracle Communications Unified Inventory Management
Oracle StorageTek ACSLS
Oracle Banking Treasury Management
Log Analysis
IBM Cloud Pak for Data System
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Oracle Endeca Information Discovery Studio
Oracle Enterprise Repository
Red Hat OpenShift Container Platform
Primavera Unifier
SecureTransport
Oracle API Gateway
Oracle TimesTen In-Memory Database
Oracle Retail Advanced Inventory Planning
Oracle Retail Financial Integration
Oracle Retail Merchandising System
Oracle Retail Merchandise Financial Planning
Oracle Retail Regular Price Optimization
Oracle Retail Replenishment Optimization
Oracle Retail Assortment Planning
Oracle Retail Category Management Planning & Optimization
Oracle Retail Size Profile Optimization
Oracle Retail Item Planning
Oracle Retail Macro Space Optimization
Oracle Retail EFTLink
Oracle Retail Predictive Application Server
Primavera Gateway
Oracle Retail Integration Bus
How to mitigate CVE-2020-11979
runc (Red Hat package) - addressed in versions 1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8
cri-o (Red Hat package) - update to 1.19.1-7.rhaos4.6.git6377f68.el7
apache-ant (Alpine package) - update to 1.10.9-r0
jenkins (Red Hat package) - addressed in versions 2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8
conmon (Red Hat package) - addressed in versions 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8
IBM Cloud Pak System - update to 2.3.3.6
python-rsa (Red Hat package) - update to 4.7-1.el8
openshift (Red Hat package) - addressed in versions 4.5.0-202102050524.p0.git.0.9229406.el7, 4.5.0-202102050524.p0.git.0.9229406.el8, 4.6.0-202102050212.p0.git.94265.716fcf8.el7, 4.6.0-202102050212.p0.git.94265.716fcf8.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8
openshift-ansible (Red Hat package) - addressed in versions 4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7
openshift-clients (Red Hat package) - addressed in versions 4.5.0-202102051529.p0.git.3612.61b096a.el7, 4.5.0-202102051529.p0.git.3612.61b096a.el8, 4.6.0-202102050644.p0.git.3831.1c61c6b.el7, 4.6.0-202102050644.p0.git.3831.1c61c6b.el8
Red Hat OpenShift Container Platform - addressed in versions 4.5.33, 4.6.17
openshift-kuryr (Red Hat package) - update to 4.6.0-202102031810.p0.git.2225.a3ab872.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.6.0-202102031810.p0.git.15.dcab90a.el8
jenkins-2-plugins (Red Hat package) - update to 4.6.1612257979-1.el8
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Oracle TimesTen In-Memory Database - update to 11.2.2.8.27
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
ant-swing - update to 1.9.4-3.12.1
ant-scripts - update to 1.9.4-3.12.1
ant - update to 1.9.4-3.12.1
ant-jmf - update to 1.9.4-3.12.1
ant-apache-log4j - update to 1.9.4-3.12.3
ant-javadoc - update to 1.9.4-3.12.3
ant-commons-logging - update to 1.9.4-3.12.3
ant-apache-resolver - update to 1.9.4-3.12.3
ant-apache-regexp - update to 1.9.4-3.12.3
ant-apache-oro - update to 1.9.4-3.12.3
ant-jdepend - update to 1.9.4-3.12.3
ant-antlr - update to 1.9.4-3.12.3
ant-apache-bcel - update to 1.9.4-3.12.3
ant-apache-bsf - update to 1.9.4-3.12.3
ant-javamail - update to 1.9.4-3.12.3
ant-junit - update to 1.9.4-3.12.3
ant-manual - update to 1.9.4-3.12.3
ant - addressed in versions 1.10.9-1.fc31, 1.10.9-1.fc32, 1.10.9-1.fc33
IBM Cloud Pak for Data System - update to 2.0.2.1
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3
External References
- https://lists.apache.org/thread.html/r107ea1b1a7a214bc72fe1a04207546ccef542146ae22952e1013b5cc@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r1dc8518dc99c42ecca5ff82d0d2de64cd5d3a4fa691eb9ee0304781e@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r2306b67f20c24942b872b0a41fbdc9330e8467388158bcd19c1094e0@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r4ca33fad3fb39d130cda287d5a60727d9e706e6f2cf2339b95729490@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/r5e1cdd79f019162f76414708b2092acad0a6703d666d72d717319305@%3Cdev.creadur.apache.org%3E
- https://lists.apache.org/thread.html/rc3c8ef9724b5b1e171529b47f4b35cb7920edfb6e917fa21eb6c64ea%40%3Cdev.ant.apache.org%3E
Related Security Bulletins
- Privilege escalation in Apache Ant
- Permissions, Privileges, and Access Controls in apache-ant (Alpine package)
- Gentoo update for Apache Ant
- Arch Linux update for ant
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in Primavera Gateway
- Multiple vulnerabilities in Oracle Enterprise Repository
- Multiple vulnerabilities in Oracle Retail Store Inventory Management
- Multiple vulnerabilities in Oracle Retail Service Backbone
- Multiple vulnerabilities in Oracle Retail Integration Bus
- Multiple vulnerabilities in Oracle Retail Financial Integration
- Multiple vulnerabilities in Oracle Banking Platform
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in Oracle Utilities Framework
- Multiple vulnerabilities in Oracle Communications Unified Inventory Management
- Multiple vulnerabilities in Oracle API Gateway
- Multiple vulnerabilities in Oracle Endeca Information Discovery Studio
- Permissions, Privileges, and Access Controls in Oracle Retail Size Profile Optimization
- Permissions, Privileges, and Access Controls in Oracle Retail Replenishment Optimization
- Permissions, Privileges, and Access Controls in Oracle Retail Regular Price Optimization
- Multiple vulnerabilities in Oracle Retail Merchandising System
- Permissions, Privileges, and Access Controls in Oracle Retail Merchandise Financial Planning
- Permissions, Privileges, and Access Controls in Oracle Retail Macro Space Optimization
- Permissions, Privileges, and Access Controls in Oracle Retail Item Planning
- Multiple vulnerabilities in Oracle Retail EFTLink
- Permissions, Privileges, and Access Controls in Oracle Retail Category Management Planning & Optimization
- Permissions, Privileges, and Access Controls in Oracle Retail Assortment Planning
- Multiple vulnerabilities in Oracle Retail Advanced Inventory Planning
- Multiple vulnerabilities in Oracle Retail Predictive Application Server
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- Multiple vulnerabilities in Oracle Banking Treasury Management
- Multiple vulnerabilities in Oracle FLEXCUBE Private Banking
- Multiple vulnerabilities in Oracle Retail Merchandising System
- Multiple vulnerabilities in Oracle Agile Engineering Data Management
- Multiple vulnerabilities in Oracle TimesTen In-Memory Database
- Multiple vulnerabilities in Oracle StorageTek Tape Analytics (STA)
- Multiple vulnerabilities in Oracle StorageTek ACSLS
- SUSE update for ant
- Multiple vulnerabilities in Oracle Utilities Network Management System
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in Axway SecureTransport (August 2022)
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Security Verify Governance
- Fedora 33 update for ant
- Fedora 32 update for ant
- Fedora 31 update for ant
- Multiple vulnerabilities in IBM webMethods BPM