CVE-2020-11979

CVE-2020-11979

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

Source: CVE-2020-11979

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다