CxJasonT / CxFlowBodgeit

CxOne PR and CxFlow webhook
0 stars 0 forks source link

CX: CVE-2020-1945 in Maven-org.apache.ant:ant and 1.8.4 @ CxFlowBodgeit.master #20

Closed CxJasonT closed 2 years ago

CxJasonT commented 3 years ago

Description

Apache Ant <1.9.15 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

MEDIUM Vulnerable Package issue exists @ org.apache.ant:ant in branch master

Vulnerability ID: CVE-2020-1945

Package Name: org.apache.ant:ant

Severity: MEDIUM

CVSS Score: 6.3

Publish Date: 2020-05-14T16:15:00

Current Package Version: 1.8.4

Remediation Upgrade Recommendation: 1.9.16

Link To SCA

Reference – NVD link