VDB

GCVE-110-MAGEIA-2021-173

GCVE-110-MAGEIA-2021-173
Advisory Published
Vulnetix · Advisory published April 3, 2021
Updated ant packages fix security vulnerability: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process(CVE-2020-11979).

Affected Products

VendorProductVersionsPlatforms
Mageiaant0 (affected), 1.10.9-1.mga7 (unaffected), 1.10.9-1.mga7 (unaffected), 0 (affected)
Mageialightspark0 (affected), 0.8.5-1.mga8 (unaffected)

Browse GCVE Records

74,496 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›