Uploaded image for project: 'Maven Antrun Plugin'
  1. Maven Antrun Plugin
  2. MANTRUN-227

Upgrade Ant to 1.10.12

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 3.0.0
    • 3.1.0

    Description

      Versions Affected: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7

       

      Medium: insecure temporary file vulnerability CVE-2020-1945

      Apache Ant uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.

      Mitigation: Ant users of versions 1.1 to 1.9.14 and 1.10.0 to 1.10.7 should set the java.io.tmpdir system property to point to a directory only readable and writable by the current user prior to running Ant.

      Users of versions 1.9.15 and 1.10.8 can use the Ant property ant.tmpfile instead. Users of Ant 1.10.8 can rely on Ant protecting the temporary files if the underlying filesystem allows it, but we still recommend using a private temporary directory instead.

      This was fixed in revisions 9c1f4d905da59bf446570ac28df5b68a37281f35041b058c7bf10a94d56db3ca9dba38cf90ab9943 and a8645a151bc706259fb1789ef587d05482d98612.

      This was first reported to the Security Team on 29 January 2020 and made public on 13 May 2020

      Affects: until 1.10.7

      Attachments

        Activity

          People

            slachiewicz Sylwester Lachiewicz
            slachiewicz Sylwester Lachiewicz
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: