CVE-2021-36374 describes a denial-of-service vulnerability in Apache Ant versions prior to 1.9.16 and 1.10.11, and consequently affects products like Oracle that utilize these Ant versions. A specially crafted ZIP archive or derived formats (e.g., JAR files, office documents) can cause an Apache Ant build to allocate excessive memory, leading to an out-of-memory error and disrupting the build process. This vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring user interaction (e.g., opening a malicious file) to achieve high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9.0, < 1.9.16CPE matchmatch criteria | cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:* | ||
>= 1.10.0, < 1.10.11CPE matchmatch criteria | cpe:2.3:a:apache:ant:*:*:*:*:*:*:*:* | ||
6.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* | ||
9.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* | ||
14.5CPE matchmatch criteria | cpe:2.3:a:oracle:banking_trade_finance:14.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Improper Handling of Length Parameter Inconsistency in Apache Ant
Aug 2, 2021Apache Ant ZIP and ZIP based archive denial of service vulerability
Jul 13, 2021ant: excessive memory allocation when reading a specially crafted ZIP archive or a derived formats
Jul 13, 2021