CVE-2021-36374
published 2021-07-14CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.62%
83.7th percentile
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ant | >= 0 < 1.10.11-1 | 1.10.11-1 |
| apache | ant | >= 0 < 1.10.11-1 | 1.10.11-1 |
| apache | ant | >= 0 < 1.10.11-1 | 1.10.11-1 |
| apache | ant | >= 1.10.0 < 1.10.11 | 1.10.11 |
| apache | ant | >= 1.9.0 < 1.9.16 | 1.9.16 |
| apache_software_foundation | apache_ant | >= 1.4 < Apache Ant* | Apache Ant* |
| apache_software_foundation | apache_ant | Apache Ant 1.10.x – 1.10.10 | — |
| apache_software_foundation | apache_ant | Apache Ant 1.9.x – 1.9.15 | — |
| debian | ant | < ant 1.10.11-1 (bookworm) | ant 1.10.11-1 (bookworm) |
| msrc | azl3_javapackages-bootstrap_1.14.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_javapackages-bootstrap_1.5.0-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_javapackages-bootstrap_1.5.0-6_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_ant_1.10.11-1_on_cbl_mariner_1.0 | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | banking_trade_finance | — | — |
| oracle | banking_treasury_management | — | — |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_diameter_intelligence_hub | 8.0.0 – 8.1.0 | — |
| oracle | communications_diameter_intelligence_hub | 8.2.0 – 8.2.3 | — |
| oracle | communications_order_and_service_management | — | — |
| oracle | communications_order_and_service_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Systems Risk Matrix: Tools (Apache Ant) — CVE-2021-36374
vendor_oracle·2024-04-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Systems Risk Matrix: Tools (Apache Ant) — CVE-2021-36374
Oracle Oracle Systems Risk Matrix: Tools (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Ant) — CVE-2021-36374
vendor_oracle·2023-10-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Ant) — CVE-2021-36374
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installer (Apache Ant) — CVE-2021-36374
vendor_oracle·2023-07-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Installer (Apache Ant) — CVE-2021-36374
Oracle Oracle Fusion Middleware Risk Matrix: Installer (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Ant) — CVE-2021-36374
vendor_oracle·2023-04-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Ant) — CVE-2021-36374
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Installation (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-10-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Installation (Apache Ant) — CVE-2021-36374
Oracle Oracle Retail Applications Risk Matrix: Installation (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle HealthCare Applications Risk Matrix: Health Policy Engine (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-07-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle HealthCare Applications Risk Matrix: Health Policy Engine (Apache Ant) — CVE-2021-36374
Oracle Oracle HealthCare Applications Risk Matrix: Health Policy Engine (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Installer, OSM SDK (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-04-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Installer, OSM SDK (Apache Ant) — CVE-2021-36374
Oracle Oracle Communications Applications Risk Matrix: Installer, OSM SDK (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Build Tool (Apache Ant) — CVE-2021-36374
vendor_oracle·2022-01-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Build Tool (Apache Ant) — CVE-2021-36374
Oracle Oracle Communications Applications Risk Matrix: Build Tool (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Ant) — CVE-2021-36374
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2021-36374 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Ant) — CVE-2021-36374
Oracle Oracle Construction and Engineering Risk Matrix: Admin (Apache Ant) vulnerability
CVE: CVE-2021-36374
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Red Hat
ant: excessive memory allocation when reading a specially crafted ZIP archive or a derived formats
vendor_redhat·2021-07-13·CVSS 5.5
CVE-2021-36374 [MEDIUM] CWE-770 ant: excessive memory allocation when reading a specially crafted ZIP archive or a derived formats
ant: excessive memory allocation when reading a specially crafted ZIP archive or a derived formats
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Statement: OpenShift Container Platform 4 (OCP) ships affected version of Apache Ant in the ose-metering-hive container, however the metering operator is deprecated since 4.6[1]. This issue is not currently planned to be addressed in future updates and hence ose-metering-hive container has been m
Microsoft
Apache Ant ZIP and ZIP based archive denial of service vulerability
vendor_msrc·2021-07-13·CVSS 5.5
CVE-2021-36374 [MEDIUM] CWE-130 Apache Ant ZIP and ZIP based archive denial of service vulerability
Apache Ant ZIP and ZIP based archive denial of service vulerability
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference:
Debian
CVE-2021-36374: ant - When reading a specially crafted ZIP archive, or a derived formats, an Apache An...
vendor_debian·2021·CVSS 5.5
CVE-2021-36374 [MEDIUM] CVE-2021-36374: ant - When reading a specially crafted ZIP archive, or a derived formats, an Apache An...
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
Scope: local
bookworm: resolved (fixed in 1.10.11-1)
bullseye: open
forky: resolved (fixed in 1.10.11-1)
sid: resolved (fixed in 1.10.11-1)
trixie: resolved (fixed in 1.10.11-1)
OSV
Improper Handling of Length Parameter Inconsistency in Apache Ant
osv·2021-08-02
CVE-2021-36374 [MEDIUM] Improper Handling of Length Parameter Inconsistency in Apache Ant
Improper Handling of Length Parameter Inconsistency in Apache Ant
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
GHSA
Improper Handling of Length Parameter Inconsistency in Apache Ant
ghsa·2021-08-02
CVE-2021-36374 [MEDIUM] CWE-130 Improper Handling of Length Parameter Inconsistency in Apache Ant
Improper Handling of Length Parameter Inconsistency in Apache Ant
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
OSV
CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to
osv·2021-07-14·CVSS 5.5
CVE-2021-36374 [MEDIUM] CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
No detection rules found.
No public exploits indexed.
https://ant.apache.org/security.htmlhttps://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3Ehttps://lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91395a96c6%40%3Cdev.myfaces.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210819-0007/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://ant.apache.org/security.htmlhttps://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3Ehttps://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3Ehttps://lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91395a96c6%40%3Cdev.myfaces.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210819-0007/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-07-14
Published