<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:32:29.865163+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-00774</id>
    <title>bdu:2021-00774</title>
    <updated>2026-10-02T15:32:29.893601+00:00</updated>
    <content>bdu:2021-00774</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-00774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-11979</id>
    <title>Withdrawn: BELL-CVE-2020-11979 — CVE-2020-11979 does not affect BellSoft software</title>
    <updated>2026-10-02T15:32:29.893646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-11979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-gradle-2020-11979</id>
    <title>BIT-gradle-2020-11979</title>
    <updated>2026-10-02T15:32:29.893665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: gradle</p>
<p>As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-gradle-2020-11979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-367</id>
    <title>certfr-2022-avi-367 — De multiples vulnérabilités ont été découvertes dans Oracle Systems.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-02T15:32:29.893696+00:00</updated>
    <content>certfr-2022-avi-367</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-367"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-tn67221</id>
    <title>CLEANSTART-2025-TN67221 — As mitigation for CVE-2020-1945 Apache Ant 1</title>
    <updated>2026-10-02T15:32:29.893712+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: apache-ant</p>
<p>Security vulnerability affects the apache-ant package. As mitigation for CVE-2020-1945 Apache Ant 1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-tn67221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-41002</id>
    <title>EUVD-2026-41002</title>
    <updated>2026-10-02T15:32:29.893732+00:00</updated>
    <content>EUVD-2026-41002</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-41002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11979</id>
    <title>fkie_cve-2020-11979</title>
    <updated>2026-10-02T15:32:29.893743+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f62v-xpxf-3v68</id>
    <title>GHSA-f62v-xpxf-3v68 — Code injection in Apache Ant</title>
    <updated>2026-10-02T15:32:29.893764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.ant:ant</p>
<p>As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f62v-xpxf-3v68"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11979</id>
    <title>gsd-2020-11979</title>
    <updated>2026-10-02T15:32:29.893783+00:00</updated>
    <content>gsd-2020-11979</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-11979</id>
    <title>msrc_CVE-2020-11979 — As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only th…</title>
    <updated>2026-10-02T15:32:29.893793+00:00</updated>
    <content>msrc_CVE-2020-11979</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-11979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10616-1</id>
    <title>openSUSE-SU-2024:10616-1 — ant-1.10.10-1.2 on GA media</title>
    <updated>2026-10-02T15:32:29.893810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ant-1.10.10-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10616-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0423</id>
    <title>RHSA-2021:0423 — Red Hat Security Advisory: OpenShift Container Platform 4.6.17 security and packages update</title>
    <updated>2026-10-02T15:32:29.893826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ant: insecure temporary file vulnerability ant: insecure temporary file jenkins: Arbitrary file read vulnerability in workspace browsers jenkins: XSS vulnerability in notification bar jenkins: Improper handling of REST API XML deserialization errors jenkins: Path traversal vulnerability in agent names jenkins: Arbitrary file existence check in file fingerprints jenkins: Excessive memory allocation in graph URLs leads to denial of service jenkins: Stored XSS vulnerability in button labels jenkins: Missing permission check for paths with specific prefix jenkins: Reflected XSS vulnerability in markup formatter preview jenkins: Stored XSS vulnerability on new item page jenkins: Filesystem traversal by privileged users</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:4022-1</id>
    <title>SUSE-SU-2022:4022-1 — Security update for ant</title>
    <updated>2026-10-02T15:32:29.893856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ant</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:4022-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11979</id>
    <title>UBUNTU-CVE-2020-11979</title>
    <updated>2026-10-02T15:32:29.893870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ant, Ubuntu:Pro:16.04:LTS: ant, Ubuntu:Pro:18.04:LTS: ant, Ubuntu:Pro:20.04:LTS: ant</p>
<p>As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0119</id>
    <title>WID-SEC-W-2023-0119 — Oracle Utilities Applications: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:32:29.893892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0119"/>
  </entry>
</feed>
