CVE-2020-1945 describes a vulnerability in Apache Ant versions 1.1 through 1.9.14 and 1.10.0 through 1.10.7, where sensitive information can be leaked due to the use of the default temporary directory. Additionally, the fixcrlf and replaceregexp tasks can allow an attacker to inject modified source files into the build process. This vulnerability has a CVSS score of 6.3 (Medium), indicating a local attack vector with high attack complexity, requiring low privileges and no user interaction, but leading to high confidentiality and integrity impacts. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, nor are there any known public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1, <= 1.9.14CPE matchmatch criteria | cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:* | ||
>= 1.10.0, <= 1.10.7CPE matchmatch criteria | cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:* | ||
19.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.