Apache Software Foundation Apache Ant vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_ant.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-36373MEDIUMCVSS 5.5≥ Apache Ant 1.9.x, ≤ 1.9.15≥ Apache Ant 1.10.x, ≤ 1.10.102021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
cvelistv5nvd
CVE-2021-36374MEDIUMCVSS 5.5≥ 1.4, < Apache Ant*≥ Apache Ant 1.9.x, ≤ 1.9.15+1 more2021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
cvelistv5nvd