Incorrect default permissions in Apache Ant - CVE-2020-1945

 

Incorrect default permissions in Apache Ant - CVE-2020-1945

Published: May 15, 2020


Vulnerability identifier: #VU27924
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1945
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to Apache Ant is using a default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process. A local user with access to the system can view contents of files and directories or modify them.


Affected software

Apache Ant
Arch Linux
Gentoo Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Opensuse
Fedora
IBM Business Automation Workflow
Oracle Banking Enterprise Collections
Oracle Real-Time Decision Server
Oracle Middleware Common Libraries and Tools
Log Analysis
IBM Cloud Pak for Data System
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
runc (Red Hat package)
cri-o (Red Hat package)
ant (Ubuntu package)
apache-ant (Alpine package)
jenkins (Red Hat package)
conmon (Red Hat package)
python-rsa (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
ant-jmf
ant-scripts
ant-swing
ant
ant-antlr
ant-apache-bcel
ant-apache-bsf
ant-apache-log4j
ant-apache-oro
ant-commons-logging
ant-apache-regexp
ant-apache-resolver
ant-javadoc
ant-javamail
ant-jdepend
ant-manual
ant-junit
Analytics Content Hub
Oracle Utilities Framework
Oracle Banking Platform
Oracle Communications ASAP
Oracle Financial Services Analytical Applications Infrastructure
webMethods BPM
Oracle FLEXCUBE Private Banking
Oracle FLEXCUBE Investor Servicing
Oracle Data Integrator
Oracle Retail Back Office
Oracle Retail Returns Management
Oracle Retail Central Office
IBM Cloud Pak System
Oracle Health Sciences Information Manager
Oracle Endeca Information Discovery Studio
Oracle Enterprise Repository
Oracle Business Process Management Suite
Oracle Banking Liquidity Management
DITA Open Toolkit
Integrated Diameter Intelligence Hub (IDIH)
Red Hat OpenShift Container Platform
Primavera Unifier
SecureTransport
Oracle Communications MetaSolv Solution
Oracle Communications Order and Service Management
Oracle Enterprise Manager Ops Center
Oracle Retail Extract Transform and Load
Oracle Retail Point of Service
Oracle Retail Integration Bus
AMQ Streams
IBM Case Manager

How to mitigate CVE-2020-1945

Install updates from vendor's website.

Apache Ant - addressed in versions 1.9.15, 1.10.8
runc (Red Hat package) - addressed in versions 1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8
cri-o (Red Hat package) - update to 1.19.1-7.rhaos4.6.git6377f68.el7
ant (Ubuntu package) - update to 1.10.6-1ubuntu0.1
apache-ant (Alpine package) - update to 1.10.8-r0
jenkins (Red Hat package) - addressed in versions 2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8
Analytics Content Hub - update to 2.2
conmon (Red Hat package) - addressed in versions 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8
IBM Cloud Pak System - update to 2.3.3.6
python-rsa (Red Hat package) - update to 4.7-1.el8
DITA Open Toolkit - update to 3.5.1
openshift (Red Hat package) - addressed in versions 4.5.0-202102050524.p0.git.0.9229406.el7, 4.5.0-202102050524.p0.git.0.9229406.el8, 4.6.0-202102050212.p0.git.94265.716fcf8.el7, 4.6.0-202102050212.p0.git.94265.716fcf8.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202102050524.p0.git.2594.ff3b8c0.el8
openshift-ansible (Red Hat package) - addressed in versions 4.5.0-202102031005.p0.git.0.c6839a2.el7, 4.6.0-202102031649.p0.git.0.bf90f86.el7
openshift-clients (Red Hat package) - addressed in versions 4.5.0-202102051529.p0.git.3612.61b096a.el7, 4.5.0-202102051529.p0.git.3612.61b096a.el8, 4.6.0-202102050644.p0.git.3831.1c61c6b.el7, 4.6.0-202102050644.p0.git.3831.1c61c6b.el8
Red Hat OpenShift Container Platform - addressed in versions 4.5.33, 4.6.17
openshift-kuryr (Red Hat package) - update to 4.6.0-202102031810.p0.git.2225.a3ab872.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.6.0-202102031810.p0.git.15.dcab90a.el8
jenkins-2-plugins (Red Hat package) - update to 4.6.1612257979-1.el8
SecureTransport - update to 5.5-20220825
webMethods BPM - update to 11.1 Fix 9
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001A
AMQ Streams - update to 1.5.0
ant-jmf - update to 1.9.4-3.12.1
ant-scripts - update to 1.9.4-3.12.1
ant-swing - update to 1.9.4-3.12.1
ant - update to 1.9.4-3.12.1
ant-antlr - update to 1.9.4-3.12.3
ant-apache-bcel - update to 1.9.4-3.12.3
ant-apache-bsf - update to 1.9.4-3.12.3
ant-apache-log4j - update to 1.9.4-3.12.3
ant-apache-oro - update to 1.9.4-3.12.3
ant-commons-logging - update to 1.9.4-3.12.3
ant-apache-regexp - update to 1.9.4-3.12.3
ant-apache-resolver - update to 1.9.4-3.12.3
ant-javadoc - update to 1.9.4-3.12.3
ant-javamail - update to 1.9.4-3.12.3
ant-jdepend - update to 1.9.4-3.12.3
ant-manual - update to 1.9.4-3.12.3
ant-junit - update to 1.9.4-3.12.3
ant - addressed in versions 1.10.8-1.fc31, 1.10.8-1.fc32
IBM Cloud Pak for Data System - update to 2.0.2.1
IBM Case Manager - update to 5.3.3-IF011
IBM Spectrum Control - update to 5.4.10.2
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Security Verify Governance - update to 10.0.2.0.3

External References

Related Security Bulletins