5.5mediumMedium
CVE-2021-36374
Apache Ant
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 5.5 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H- Weakness
- CWE-130
- Assigned by
- security@apache.org
Dates
- Published
- 2021-07-14
- Last modified
- 2026-08-25
- Sources
- NVD
Affected products
- Apache Ant1.9.0 - 1.9.16, 1.10.0 - 1.10.11
- Oracle Agile Engineering Data Management6.2.1.0
- Oracle Agile Product Lifecycle Management9.3.6
- Oracle Banking Trade Finance14.5
- Oracle Banking Treasury Management14.5
- Oracle Communications Cloud Native Core Automated Test Suite1.9.0
- Oracle Communications Cloud Native Core Binding Support Function1.11.0
- Oracle Communications Diameter Intelligence Hub8.0.0 - 8.1.0, 8.2.0 - 8.2.3
- Oracle Communications Order And Service Management7.3, 7.4
- Oracle Communications Unified Inventory Management7.3.0, 7.4.0, 7.4.1, 7.4.2, 7.5.0
- Oracle Enterprise Repository11.1.1.7.0
- Oracle Financial Services Analytical Applications Infrastructure8.0.6 - 8.1.1
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://ant.apache.org/security.html
- https://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3E
- https://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3E
- https://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3E
- https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3E
- https://lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91395a96c6%40%3Cdev.myfaces.apache.org%3E
- https://security.netapp.com/advisory/ntap-20210819-0007/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://ant.apache.org/security.html
- https://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3E
- https://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3E
- https://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3E