diff --git a/manual/running.html b/manual/running.html index ab48f95ac..e31ec34cc 100644 --- a/manual/running.html +++ b/manual/running.html @@ -523,6 +523,15 @@ on the platform and the JVM implementation.
usejava.io.tmpdir
unless they have been adapted to the
changed API of Ant 1.10.8.
+Security Note: Using the default temporary directory
+specified by java.io.tmpdir
can result in the leakage of
+sensitive information or possibly allow an attacker to execute
+arbitrary code. This is especially true in multi-user environments. It
+is recommended that ant.tmpdir
be set to a directory
+owned by the user running Ant with 0700 permissions. Ant 1.10.8 and
+later will try to make temporary files created by it only
+readable/writable by the current user but may silently fail to do so
+depending on the OS and filesystem.