Miggo Logo

CVE-2020-1945: Sensitive Data Exposure in Apache Ant

6.3

CVSS Score
3.1

Basic Information

EPSS Score
0.0375%
Published
9/14/2020
Updated
2/1/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.ant:antmaven>= 1.1, < 1.9.151.9.15
org.apache.ant:antmaven>= 1.10.0, < 1.10.81.10.8

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The analysis is based on the understanding of the vulnerability and the patches applied to the affected tasks in Apache Ant. The FixCRLF and ReplaceRegExp tasks were identified as vulnerable due to their insecure handling of temporary files. The patches for these tasks modify the temporary file creation to use more secure methods, thus mitigating the vulnerability.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*p**** *nt *.* to *.*.** *n* *.**.* to *.**.* us*s t** ****ult t*mpor*ry *ir**tory i**nti*i** *y t** J*v* syst*m prop*rty j*v*.io.tmp*ir *or s*v*r*l t*sks *n* m*y t*us l**k s*nsitiv* in*orm*tion. T** *ix*rl* *n* r*pl***r***xp t*sks *lso *opy *il*s *r

Reasoning

T** *n*lysis is **s** on t** un**rst*n*in* o* t** vuln*r**ility *n* t** p*t***s *ppli** to t** *****t** t*sks in *p**** *nt. T** *ix*RL* *n* R*pl***R***xp t*sks w*r* i**nti*i** *s vuln*r**l* *u* to t**ir ins**ur* **n*lin* o* t*mpor*ry *il*s. T** p*t*